CVE-2005-4622

efilego 3.01 - Directory Traversal and Arbitrary File Upload via Triple Dot in URL

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2005-4622. PoCs published by dr_insane.

AI-analyzed exploit summary The provided text describes multiple input validation vulnerabilities in eFileGo, including directory traversal and arbitrary command execution. It includes example URLs demonstrating exploitation but lacks executable code.

Description

Directory traversal vulnerability in eFileGo 3.01 allows remote attackers to execute arbitrary code, read arbitrary files, and upload arbitrary files via a ... (triple dot) in (1) the URL on port 608 and (2) the argument to upload.exe.

Exploits (1)

exploitdb WRITEUP VERIFIED
by dr_insane · textremotewindows
https://www.exploit-db.com/exploits/27024

The provided text describes multiple input validation vulnerabilities in eFileGo, including directory traversal and arbitrary command execution. It includes example URLs demonstrating exploitation but lacks executable code.

Classification
Writeup 90%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: eFileGo (version not specified)
No auth needed
Prerequisites: Network access to the vulnerable application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Exploit vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1015430
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/16124
Exploit vdb-entry x_refsource_osvdb
http://www.osvdb.org/22151
Exploit, Vendor Advisory x_refsource_misc
http://www.ipomonis.com/advisories/PaQFile_Share.txt
Exploit, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/18279

Scores

EPSS 0.0433
EPSS Percentile 89.9%

Details

Status published
Products (1)
efilego/efilego 3.0.1
Published Dec 31, 2005
Tracked Since Feb 18, 2026