PT-2005-1540 · Glftpd · Glftpd

Published

2005-02-19

·

Updated

2017-07-11

·

CVE-2005-0483

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Glftpd versions 1.26 through 2.00
Description The issue allows remote authenticated users to determine the existence of arbitrary files, list files in restricted directories, or read arbitrary files from within ZIP or gzip files. This is achieved via .. (dot dot) sequences and globbing (*) characters in a SITE NFO command.
Recommendations For Glftpd versions 1.26 through 2.00, consider restricting access to the SITE NFO command until a patch is available, and avoid using .. (dot dot) sequences and globbing (*) characters in this command to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-0483

Affected Products

Glftpd