6.5
CVSSv2

CVE-2010-2695

Published: 12/07/2010 Updated: 10/10/2018
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Directory traversal vulnerability in the SFTP/SSH2 virtual server in Xlight FTP Server 3.5.0, 3.5.5, and possibly other versions prior to 3.6 allows remote authenticated users to read, overwrite, or delete arbitrary files via .. (dot dot) sequences in the (1) ls, (2) rm, (3) rename, and other unspecified commands.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

xlightftpd xlight ftp server 3.5

xlightftpd xlight ftp server 3.5.5