7.5
CVSSv2

CVE-2001-1109

Published: 12/09/2001 Updated: 14/02/2024
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Directory traversal vulnerability in EFTP 2.0.7.337 allows remote authenticated users to reveal directory contents via a .. (dot dot) in the (1) LIST, (2) QUOTE SIZE, and (3) QUOTE MDTM commands.

Vulnerable Product Search on Vulmon Subscribe to Product

khamil landross and zack jones eftp 2.0.7.337

Exploits

source: wwwsecurityfocuscom/bid/3333/info A user can confirm the existence and location of files and directory structure information, by submitting a 'size' or 'mdtm' command of a file If the command is carried out by the vulnerable service, the attacker can confirm the location of the file Submitting a 'size' or 'mdtm' command for a f ...