PT-2001-1947 · Guildftpd · Guildftpd
Published
2001-10-12
·
Updated
2008-09-05
·
CVE-2001-0767
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
GuildFTPd version 0.9.7
Description:
A directory traversal issue allows attackers to list or read arbitrary files and directories by using a .. in either the LS or GET commands.
Recommendations:
For GuildFTPd version 0.9.7, update to a version that fixes this issue, as using .. in commands can lead to unauthorized access to files and directories.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Guildftpd