Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2001-0582

Overview

Vulnerability Score 4.6 4.6
CVE Id CVE-2001-0582
Last Modified 03 Apr 2009 12:08:31
Published 22 Aug 2001 12:00:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector LOCAL
Access Complexity LOW
Authentication NONE

CVE-2001-0582

Summary

Ben Spink CrushFTP FTP Server 2.1.6 and earlier allows a local attacker to access arbitrary files via a '..' (dot dot) attack, or variations, in (1) GET, (2) CD, (3) NLST, (4) SIZE, (5) RETR.

Vulnerable Systems

Application

  • Ben Spink Crushftp Ftp Server 2.1.4

  • Ben Spink Crushftp Ftp Server 2.1.6


References

CERT-VN - VU#110803

XF - crushftp-directory-traversal(6495)

BUGTRAQ - 20010503 Vulnerabilities in CrushFTP Server


Last Updated: 27 May 2016 10:36:18