4.6
CVSSv2

CVE-2001-0582

Published: 22/08/2001 Updated: 19/12/2017
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Ben Spink CrushFTP FTP Server 2.1.6 and previous versions allows a local malicious user to access arbitrary files via a '..' (dot dot) attack, or variations, in (1) GET, (2) CD, (3) NLST, (4) SIZE, (5) RETR.

Vulnerable Product Search on Vulmon Subscribe to Product

ben spink crushftp ftp server 2.1.4

ben spink crushftp ftp server