PT-2011-5052 · Zftp · Zftpserver Suite

Published

2011-12-20

·

Updated

2011-12-20

·

CVE-2011-4717

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions zFTPServer Suite version 6.0.0.52
Description A directory traversal issue allows remote authenticated users to delete arbitrary directories by sending a crafted RMD command.
Recommendations For version 6.0.0.52, update to a version that fixes this issue to prevent remote authenticated users from deleting arbitrary directories.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-4717

Affected Products

Zftpserver Suite