PT-2007-1230 · Conti · Conti Ftpserver
Published
2007-01-23
·
Updated
2017-07-29
·
CVE-2006-6950
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Conti FTPServer version 1.0 Build 2.8
Description:
A directory traversal issue allows remote attackers to read arbitrary files and list arbitrary directories by including a .. (dot dot) in a filename argument.
Recommendations:
For Conti FTPServer version 1.0 Build 2.8, consider restricting access to sensitive files and directories until a patch is available. As a temporary workaround, avoid using the .. (dot dot) sequence in filename arguments to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Conti Ftpserver