Description
Directory traversal vulnerability in X-Diesel Unreal Commander 0.92 build 565 and 573 allows remote FTP servers to create or overwrite arbitrary files via a .. (dot dot) in a filename. NOTE: this can be leveraged for code execution by writing to a Startup folder.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Gynvael Coldwind · pythonremotewindows
https://www.exploit-db.com/exploits/30569
References (6)
Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/39615
Third Party Advisory third-party-advisory
x_refsource_sreason
http://securityreason.com/securityalert/3125
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/478728/100/0/threaded
Exploit x_refsource_misc
http://blog.hispasec.com/lab/advisories/adv_UnrealCommander_0_92_build_573_Multiple_FTP_Based_Vulnerabilities.txt
Exploit vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/25583
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/26739
Scores
EPSS
0.0559
EPSS Percentile
90.3%
Details
CWE
CWE-22
Status
published
Products (2)
x-diesel/unreal_commander
0.92_build565
x-diesel/unreal_commander
0.92_build573
Published
Sep 12, 2007
Tracked Since
Feb 18, 2026