PT-2003-2244 · Baby Ftp Server · Baby Ftp Server
Published
2003-12-31
·
Updated
2016-11-28
·
CVE-2003-1299
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Baby FTP Server versions prior to May 31, 2003
Description
A directory traversal issue allows remote authenticated users to list arbitrary directories and possibly read files by manipulating the CWD command with "..." (triple dot) sequences.
Recommendations
For versions prior to May 31, 2003, consider restricting access to the CWD command or limiting the ability to manipulate directory paths until a fix is available.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Baby Ftp Server