5
CVSSv2

CVE-2008-1221

Published: 10/03/2008 Updated: 11/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Absolute path traversal vulnerability in the FTP server in MicroWorld eScan Corporate Edition 9.0.742.98 and eScan Management Console (aka eScan Server) 9.0.742.1 allows remote malicious users to read arbitrary files via an absolute pathname in the RETR (get) command.

Vulnerable Product Search on Vulmon Subscribe to Product

microworld technologies escan 9.0.742.98

microworld technologies escan management console 9.0.742.1

microworld technologies escan server 9.0.742.1

Exploits

source: wwwsecurityfocuscom/bid/28127/info MicroWorld eScan Server is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input data Exploiting this issue allows an attacker to access arbitrary files outside of the FTP server root directory This can expose sensitive information that coul ...