[Forgot Password]
Login  Register Subscribe

23631

 
 

115084

 
 

97559

 
 

909

 
 

78730

 
 

109

Paid content will be excluded from the download.


Download | Alert*
CVE
view XML

CVE-2001-0054

Date: (C)2001-02-16   (M)2017-10-10
 
CVSS Score: 5.0Access Vector: NETWORK
Exploitability Subscore: 10.0Access Complexity: LOW
Impact Subscore: 2.9Authentication: NONE
 Confidentiality: PARTIAL
 Integrity: NONE
 Availability: NONE











Directory traversal vulnerability in FTP Serv-U before 2.5i allows remote attackers to escape the FTP root and read arbitrary files by appending a string such as "/..%20." to a CD command, a variant of a .. (dot dot) attack.

Reference:
http://archives.neohapsis.com/archives/bugtraq/2000-12/0043.html
http://marc.info/?l=bugtraq&m=97604119024280&w=2
BID-2052
OSVDB-464
ftp-servu-homedir-travers

CPE    1
cpe:/a:serv-u:serv-u:3.0.0.16
CWE    1
CWE-22

© 2013 SecPod Technologies