PT-2010-4217 · Xlight · Xlight Ftp Server

Publicado

2010-07-12

·

Atualizado

2018-10-10

·

CVE-2010-2695

CVSS v2.0

6.5

Média

VetorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Xlight FTP Server versions 3.5.0 through 3.5.5
Description The issue allows remote authenticated users to read, overwrite, or delete arbitrary files via .. (dot dot) sequences in commands such as ls, rm, and rename.
Recommendations For versions 3.5.0 through 3.5.5, update to version 3.6 or later to resolve the issue.

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-2695

Produtos afetados

Xlight Ftp Server