7.5
CVSSv2

CVE-2001-0263

Published: 18/06/2001 Updated: 19/12/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Gene6 G6 FTP Server 2.0 (aka BPFTP Server 2.10) allows malicious users to read file attributes outside of the web root via the (1) SIZE and (2) MDTM commands when the "show relative paths" option is not enabled.

Vulnerable Product Search on Vulmon Subscribe to Product

gene6 g6 ftp server 2.0

Exploits

source: wwwsecurityfocuscom/bid/2537/info A user can confirm the existence and location of files and directory structure information, by submitting a 'size' or 'mdtm' command of a file If the command is carried out by the vulnerable service, the attacker can confirm the location of the file Submitting a 'size' or 'mdtm' command for a f ...