CVE-2008-4501
Serv-U File Server 7.0.0.1-7.3 - Authenticated Path Traversal via RNTO Command
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-4501. PoCs published by dmnt.
AI-analyzed exploit summary This exploit demonstrates a directory traversal vulnerability in Serv-U FTP Server versions <= 7.2.0.1 and 7.3, allowing an authenticated user to overwrite arbitrary files (e.g., boot.ini) by leveraging the RNTO command with path traversal sequences.
Description
Directory traversal vulnerability in the FTP server in Serv-U 7.0.0.1 through 7.3, including 7.2.0.1, allows remote authenticated users to overwrite or create arbitrary files via a ..\ (dot dot backslash) in the RNTO command.
Exploits (1)
This exploit demonstrates a directory traversal vulnerability in Serv-U FTP Server versions <= 7.2.0.1 and 7.3, allowing an authenticated user to overwrite arbitrary files (e.g., boot.ini) by leveraging the RNTO command with path traversal sequences.