PT-2009-6358 · Golden Ftp Server · Golden Ftp Server

Sharpe

·

Published

2009-12-03

·

Updated

2024-01-26

·

CVE-2009-4194

CVSS v2.0

6.0

Medium

VectorAV:N/AC:M/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Golden FTP Server versions 4.30 through 4.50
Description The issue allows remote authenticated users to delete arbitrary files via a .. (dot dot) in the DELE command. This is a directory traversal vulnerability.
Recommendations For Golden FTP Server versions 4.30 through 4.50, consider restricting access to the DELE command until a patch is available. As a temporary workaround, avoid using the DELE command with a .. (dot dot) in the command string until the issue is resolved.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2009-4194

Affected Products

Golden Ftp Server