CVE-2002-0978

Microsoft File Transfer Manager - Arbitrary File Upload and Download via Persist Function

Title source: llm
STIX 2.1

Description

Microsoft File Transfer Manager (FTM) ActiveX control before 4.0 allows remote attackers to upload or download arbitrary files to arbitrary locations via a man-in-the-middle attack with modified TGT and TGN parameters in a call to the "Persist" function.

References (1)

Core 1
Core References
Vendor Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2002-08/0189.html

Scores

EPSS 0.0835
EPSS Percentile 94.4%

Details

Status published
Products (1)
microsoft/file_transfer_manager
Published Sep 24, 2002
Tracked Since Feb 18, 2026