8.1
CVSSv3

CVE-2009-4194

Published: 03/12/2009 Updated: 26/01/2024
CVSS v2 Base Score: 6 | Impact Score: 6.4 | Exploitability Score: 6.8
CVSS v3 Base Score: 8.1 | Impact Score: 5.2 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P

Vulnerability Summary

Directory traversal vulnerability in Golden FTP Server 4.30 Free and Professional, 4.50, and possibly other versions allows remote authenticated users to delete arbitrary files via a .. (dot dot) in the DELE command. NOTE: some of these details are obtained from third party information.

Vulnerable Product Search on Vulmon Subscribe to Product

kmint21 golden ftp server 4.30

kmint21 golden ftp server 4.50

Exploits

# Exploit Title: [Golden FTP Server File Deletion Vulnerability] # Date: [18112009] # Author: [sharpe] # Software Link: [wwwgoldenftpservercom/downloadhtml] # Version: [430 Free and Professional] # Tested on: [Windows XP SP3] # CVE : [if exists] # Code : [blogsat0ricom/?p=292] #--- #sat0ri - sudden enlightenment #blog ...