CVE-2008-2822
3D-FTP Client 8.01 - Path Traversal via LIST or MLSD Command Response
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-2822. PoCs published by Tan Chew Keong.
AI-analyzed exploit summary This exploit demonstrates directory traversal vulnerabilities in 3D-FTP by crafting malicious responses to LIST and MLSD commands, allowing arbitrary file writes outside the intended directory. The PoC includes examples with backslashes, forward-slashes, and combinations to bypass sanitization.
Description
Multiple directory traversal vulnerabilities in the FTP client in 3D-FTP Client 8.01 (8.0 build 1) allow remote FTP servers to create or overwrite arbitrary files via a .. (dot dot) in a response to a (1) LIST or (2) MLSD command.
Exploits (1)
This exploit demonstrates directory traversal vulnerabilities in 3D-FTP by crafting malicious responses to LIST and MLSD commands, allowing arbitrary file writes outside the intended directory. The PoC includes examples with backslashes, forward-slashes, and combinations to bypass sanitization.