PT-2002-2950 · Kunani · Kunani Odbc Ftp Server
Published
2002-12-31
·
Updated
2017-07-29
·
CVE-2002-2238
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
Kunani ODBC FTP Server version 1.0.10
Description:
The issue allows remote attackers to read arbitrary files by exploiting a directory traversal vulnerability. This is achieved by including a ".." (dot dot backslash) in a GET request, enabling access to files outside the intended directory.
Recommendations:
For version 1.0.10, consider restricting access to sensitive files and directories until a patch is available. As a temporary workaround, limit the use of GET requests that could be used to exploit the directory traversal vulnerability.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kunani Odbc Ftp Server