Description
Gene6 G6 FTP Server 2.0 (aka BPFTP Server 2.10) allows attackers to read file attributes outside of the web root via the (1) SIZE and (2) MDTM commands when the "show relative paths" option is not enabled.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Rob Beck · perlremotewindows
https://www.exploit-db.com/exploits/20726
Scores
EPSS
0.0401
EPSS Percentile
88.5%
Details
Status
published
Products (1)
gene6/g6_ftp_server
2.0
Published
Jun 18, 2001
Tracked Since
Feb 18, 2026