PT-2001-2087 · Cooolsoft · Cooolsoft Powerftp Server
Published
2001-11-28
·
Updated
2016-10-18
·
CVE-2001-0934
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Cooolsoft PowerFTP Server version 2.03
Description
The issue allows remote attackers to obtain the physical path of the server root via the
pwd command, which lists the full pathname.Recommendations
For Cooolsoft PowerFTP Server version 2.03, consider restricting access to the
pwd command as a temporary workaround until a patch is available.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cooolsoft Powerftp Server