4
CVSSv2

CVE-2004-2487

Published: 31/12/2004 Updated: 14/02/2024
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 405
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in Nexgen FTP Server prior to 2.2.3.23 allows remote authenticated users to read or list arbitrary files via (1) "..", (2) "\..\" (backslash dot dot), or (3) "/../" sequences in (a) RETR (get), (b) NLST (ls), (c) LIST (ls), (d) RNFR, or (e) RNTO FTP commands.

Vulnerable Product Search on Vulmon Subscribe to Product

Exploits

source: wwwsecurityfocuscom/bid/9970/info It has been reported that the Nexgen FTP server is prone to a remote directory traversal vulnerability This issue is due to a failure of the application to properly sanitize file request strings from authenticated users Successful exploitation of this vulnerability may allow a remote attacker t ...