9.3
CVSSv2

CVE-2008-5175

Published: 19/11/2008 Updated: 08/08/2017
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Directory traversal vulnerability in the FTP client in AceFTP Freeware 3.80.3 and AceFTP Pro 3.80.3 allows remote FTP servers to create or overwrite arbitrary files via a .. (dot dot) in a response to a LIST command, a related issue to CVE-2002-1345.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

visicommedia aceftp 3.80.3

Exploits

source: wwwsecurityfocuscom/bid/29989/info AceFTP is prone to a directory-traversal vulnerability because the application fails to sufficiently sanitize user-supplied input Exploiting this issue allows an attacker to write arbitrary files to locations outside of the application's current directory This could help the attacker launch fu ...