PT-2008-6319 · Visicom Media · Aceftp Freeware+1

Tan Chew Keong

·

Published

2008-11-19

·

Updated

2017-08-08

·

CVE-2008-5175

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions AceFTP Freeware version 3.80.3 AceFTP Pro version 3.80.3
Description A directory traversal issue in the FTP client allows remote FTP servers to create or overwrite arbitrary files by including a .. (dot dot) in a response to a LIST command.
Recommendations For AceFTP Freeware version 3.80.3, consider disabling the FTP client functionality until a patch is available. For AceFTP Pro version 3.80.3, restrict access to the FTP client to minimize the risk of exploitation.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-5175

Affected Products

Aceftp Freeware
Aceftp Pro