PT-2008-3976 · Core Ftp · Core Ftp Client

Tan Chew Keong

·

Published

2008-06-03

·

Updated

2017-08-08

·

CVE-2008-2519

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Core FTP client version 2.1 Build 1565
Description A directory traversal issue allows remote FTP servers to create or overwrite arbitrary files by using .. (dot dot) sequences in responses to LIST commands. This can potentially be leveraged for code execution by writing to a Startup folder.
Recommendations For Core FTP client version 2.1 Build 1565, consider disabling the LIST command functionality until a patch is available to prevent remote FTP servers from exploiting this issue. Restrict access to sensitive folders, such as Startup folders, to minimize the risk of code execution. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-2519

Affected Products

Core Ftp Client