Exploitation Summary
EIP tracks 1 public exploit for CVE-2001-0255. PoCs published by SNS Research.
AI-analyzed exploit summary This exploit demonstrates an information disclosure vulnerability in Faststream FTP++ Server, allowing a remote user to list directory contents outside the intended FTP root by issuing an 'ls' command with a drive name. The vulnerability arises due to improper path handling in the server.
Description
FaSTream FTP++ Server 2.0 allows remote attackers to list arbitrary directories by using the "ls" command and including the drive letter name (e.g. C:) in the requested pathname.
Exploits (1)
This exploit demonstrates an information disclosure vulnerability in Faststream FTP++ Server, allowing a remote user to list directory contents outside the intended FTP root by issuing an 'ls' command with a drive name. The vulnerability arises due to improper path handling in the server.