CVE-2001-1109

EFTP 2.0.7.337 - Authenticated Directory Traversal via LIST QUOTE SIZE and QUOTE MDTM Commands

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2001-1109. PoCs published by byterage.

AI-analyzed exploit summary This Perl script exploits an information leakage vulnerability in certain FTP servers by using the SIZE or MDTM commands with wildcards to map directory structures outside the FTP root. It brute-forces filenames and paths to disclose unpublished filesystem information.

Description

Directory traversal vulnerability in EFTP 2.0.7.337 allows remote authenticated users to reveal directory contents via a .. (dot dot) in the (1) LIST, (2) QUOTE SIZE, and (3) QUOTE MDTM commands.

Exploits (1)

exploitdb WORKING POC VERIFIED
by byterage · perlremotewindows
https://www.exploit-db.com/exploits/21110

This Perl script exploits an information leakage vulnerability in certain FTP servers by using the SIZE or MDTM commands with wildcards to map directory structures outside the FTP root. It brute-forces filenames and paths to disclose unpublished filesystem information.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: EFTP v2.0.7.337, GuildFTPd v0.992
Auth required
Prerequisites: FTP server access with valid credentials · Vulnerable FTP server version
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
URL Repurposed x_refsource_misc
http://www.eftp.org/releasehistory.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/7113
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/7114
Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/3331
Vendor Advisory mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/213647
Exploit, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/3333

Scores

EPSS 0.0798
EPSS Percentile 94.0%

Details

Status published
Products (1)
khamil_landross_and_zack_jones/eftp 2.0.7.337
Published Sep 12, 2001
Tracked Since Feb 18, 2026