4
CVSSv2

CVE-2009-4800

Published: 22/04/2010 Updated: 19/09/2017
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 405
Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N

Vulnerability Summary

Directory traversal vulnerability in Sysax Multi Server 4.3 and 4.5 allows remote authenticated users to delete arbitrary files via a ..// (dot dot slash slash) in a DELE command.

Vulnerable Product Search on Vulmon Subscribe to Product

sysax multi server 4.3

sysax multi server 4.5

Exploits

/* Sysax Multi Server v43 Remote Delete Files Server FTP wwwsysaxcom/ ------------------------------------------------------------------------------------- A vulnerability is caused due to an input validation error when handling FTP "DELE" requests This can be exploited to escape the FTP root and delete arbitrary files on the system ...