PT-2005-3062 · Microsoft · Windows Server 2003+3
Published
2005-10-21
·
Updated
2018-10-12
·
CVE-2005-2126
CVSS v2.0
2.6
Low
| Vector | AV:N/AC:H/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
Windows XP version SP1
Windows Server 2003 (affected versions not specified)
Internet Explorer 6 version SP1 on Windows 2000 version SP4
Description:
The issue allows remote FTP servers to overwrite files in arbitrary locations via crafted filenames when the "Enable Folder View for FTP Sites" option is enabled and a user manually initiates a file transfer.
Recommendations:
For Windows XP SP1, update the FTP client to prevent remote FTP servers from overwriting files.
For Windows Server 2003, apply the necessary configuration changes to restrict file transfer capabilities.
For Internet Explorer 6 SP1 on Windows 2000 SP4, disable the "Enable Folder View for FTP Sites" option to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Internet Explorer 6
Windows 2000
Windows Server 2003
Windows Xp