CVE-2002-0978
Microsoft File Transfer Manager - Arbitrary File Upload and Download via Persist Function
Title source: llmDescription
Microsoft File Transfer Manager (FTM) ActiveX control before 4.0 allows remote attackers to upload or download arbitrary files to arbitrary locations via a man-in-the-middle attack with modified TGT and TGN parameters in a call to the "Persist" function.
References (1)
Core 1
Core References
Vendor Advisory mailing-list
x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2002-08/0189.html
Scores
EPSS
0.0835
EPSS Percentile
94.4%
Details
Status
published
Products (1)
microsoft/file_transfer_manager
Published
Sep 24, 2002
Tracked Since
Feb 18, 2026