PT-2001-2459 · Cesarftp · Cesarftp
Published
2001-05-27
·
Updated
2008-09-10
·
CVE-2001-1335
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
CesarFTP versions 0.98b and earlier
Description
A directory traversal issue allows remote authenticated users, such as anonymous, to read arbitrary files. This is achieved by sending a GET request with a filename that contains a ...%5c (modified dot dot).
Recommendations
For versions 0.98b and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cesarftp