5
CVSSv2

CVE-2001-1335

Published: 27/05/2001 Updated: 10/09/2008
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in CesarFTP 0.98b and previous versions allows remote authenticated users (such as anonymous) to read arbitrary files via a GET with a filename that contains a ...%5c (modified dot dot).

Vulnerable Product Search on Vulmon Subscribe to Product

aclogic cesarftp 0.98b

Exploits

source: wwwsecurityfocuscom/bid/2786/info CesarFTP is a freely available FTP Server for Microsoft Windows 9x/ME systems CesarFTP on Windows 98/Me platforms contains a 'directory traversal' vulnerability If a user requests to change directories to "" from within a mapped directory, they will change into the directory above the 'real ...