20010119 Multiple Vulnerabilities In FaSTream FTP++ (+ ICS Tftpserver DoS)mailing list
http://marc.info/?l=bugtraq&m=98021181215325&w=2 CVE-2001-0255
fastream ftp++ 2.0 - Directory Traversal
Record summary
CVE-2001-0255 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.
Description
FaSTream FTP++ Server 2.0 allows remote attackers to list arbitrary directories by using the "ls" command and including the drive letter name (e.g. C:) in the requested pathname.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBfastream ftp++ 2.0 - Directory TraversalExploitDB exploitby SNS ResearchNot analyzed1 file
References
42267vdb entry
http://www.securityfocus.com/bid/2267 fastream-ftp-path-disclosure(5977)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/5977 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2001-0255