CVE-2005-2126

Windows XP/Server 2003 - Path Traversal

Title source: llm
STIX 2.1

Description

The FTP client in Windows XP SP1 and Server 2003, and Internet Explorer 6 SP1 on Windows 2000 SP4, when "Enable Folder View for FTP Sites" is enabled and the user manually initiates a file transfer, allows user-assisted, remote FTP servers to overwrite files in arbitrary locations via crafted filenames.

References (11)

Core 11
Core References
Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/415828
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1015036
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1284
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/17223
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1416
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1146
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/17172
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/17163

Scores

EPSS 0.1426
EPSS Percentile 96.2%

Details

Status published
Products (4)
microsoft/ie 6.0 sp1
microsoft/windows_2000
microsoft/windows_2003_server r2
microsoft/windows_xp
Published Oct 21, 2005
Tracked Since Feb 18, 2026