CVE-2004-1376

Microsoft Internet Explorer 5.01, 5.5, 6.0 - Directory Traversal via FTP LIST Command

Title source: llm
STIX 2.1

Description

Directory traversal vulnerability in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote malicious FTP servers to overwrite arbitrary files via .. (dot dot) sequences in filenames returned from a LIST command.

References (3)

Core 3
Core References
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/13704
Exploit, Vendor Advisory x_refsource_misc
http://www.7a69ezine.org/node/view/176
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=110461358930103&w=2

Scores

EPSS 0.0891
EPSS Percentile 94.7%

Details

Status published
Products (3)
microsoft/internet_explorer 5.01
microsoft/internet_explorer 5.5
microsoft/internet_explorer 6.0
Published Dec 30, 2004
Tracked Since Feb 18, 2026