PT-2011-5052 · Zftp · Zftpserver Suite
Published
2011-12-20
·
Updated
2011-12-20
·
CVE-2011-4717
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
zFTPServer Suite version 6.0.0.52
Description
A directory traversal issue allows remote authenticated users to delete arbitrary directories by sending a crafted RMD command.
Recommendations
For version 6.0.0.52, update to a version that fixes this issue to prevent remote authenticated users from deleting arbitrary directories.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zftpserver Suite