PT-2008-4261 · 3D Ftp · 3D-Ftp Client
Published
2008-06-23
·
Updated
2017-08-08
·
CVE-2008-2822
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
3D-FTP Client version 8.01 (8.0 build 1)
Description
The issue concerns multiple directory traversal vulnerabilities in the FTP client. These vulnerabilities allow remote FTP servers to create or overwrite arbitrary files by including a .. (dot dot) in responses to certain commands, specifically the LIST or MLSD commands.
Recommendations
For 3D-FTP Client version 8.01 (8.0 build 1), consider restricting access to the FTP client until a fix is available, and avoid using the LIST and MLSD commands on untrusted FTP servers to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
3D-Ftp Client