eftp.org
http://www.eftp.org/releasehistory.html CVE-2001-1109
EFTP Server 2.0.7.337 - Directory Existence / File Existence
Record summary
CVE-2001-1109 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
Directory traversal vulnerability in EFTP 2.0.7.337 allows remote authenticated users to reveal directory contents via a .. (dot dot) in the (1) LIST, (2) QUOTE SIZE, and (3) QUOTE MDTM commands.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBEFTP Server 2.0.7.337 - Directory Existence / File ExistenceExploitDB exploitby byterageNot analyzed1 file
References
720010912 EFTP Version 2.0.7.337 vulnerabilitiesmailing list
http://www.securityfocus.com/archive/1/213647 3331vdb entry
http://www.securityfocus.com/bid/3331 3333vdb entry
http://www.securityfocus.com/bid/3333 eftp-list-directory-traversal(7113)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/7113 eftp-quote-reveal-information(7114)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/7114 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2001-1109