10
CVSSv2

CVE-2004-0676

Published: 06/08/2004 Updated: 14/02/2024
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Directory traversal vulnerability in Fastream NETFile FTP/Web Server 6.7.2.1085 and previous versions allows remote malicious users to create or delete arbitrary files via .. (dot dot) and // (double slash) sequences in the filename parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

fastream netfile ftp web server 6.5.1.980

fastream netfile ftp web server 6.7.2.1085

fastream netfile ftp web server 6.5.1.981

Exploits

source: wwwsecurityfocuscom/bid/10658/info The NetFile FTP/Web Server is reported prone to a directory traversal vulnerability due to insufficient sanitization of user-supplied data This can allow an attacker to create, view, and delete arbitrary files outside the web root Fastream NetFILE FTP/Web Server versions 6721085 and prior a ...