CVE-2008-2795

IDM Computer Solutions Ultraedit - Path Traversal

Title source: rule
STIX 2.1

Description

Directory traversal vulnerability in the FTP and SFTP clients in IDM Computer Solutions Inc UltraEdit 14.00b allows remote FTP servers to create or overwrite arbitrary files via a .. (dot dot) or a ..\ (dot dot backslash) in a response to a LIST command.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Tan Chew Keong · textremotemultiple
https://www.exploit-db.com/exploits/31936

References (5)

Core 5
Core References
Exploit third-party-advisory x_refsource_secunia
http://secunia.com/advisories/30749
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/43149
Exploit x_refsource_misc
http://vuln.sg/ultraedit1400b-en.html
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/29784
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/1864/references

Scores

EPSS 0.0314
EPSS Percentile 86.9%

Details

CWE
CWE-22
Status published
Products (1)
idm_computer_solutions_inc/ultraedit 14.00b
Published Jun 20, 2008
Tracked Since Feb 18, 2026