PT-2001-1492 · Gene6 · Gene6 G6 Ftp Server+1
Published
2001-05-24
·
Updated
2017-12-19
·
CVE-2001-0263
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Gene6 G6 FTP Server version 2.0 (aka BPFTP Server 2.10)
Description
The issue allows attackers to read file attributes outside of the web root using the (1) SIZE and (2) MDTM commands when the "show relative paths" option is not enabled.
Recommendations
For Gene6 G6 FTP Server version 2.0 (aka BPFTP Server 2.10), consider enabling the "show relative paths" option to prevent attackers from reading file attributes outside of the web root via the SIZE and MDTM commands.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Bpftp Server
Gene6 G6 Ftp Server