CVE-2009-1031
Serv-U File Server 7.0.0.1-7.4.0.1 - Unauthenticated Directory Traversal via FTP MKD Command
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-1031. PoCs published by Jonathan Salwan.
AI-analyzed exploit summary This exploit leverages a directory traversal vulnerability in FTP Serv-U via the MKD command, allowing an attacker to escape the FTP root and create arbitrary directories on the system. It requires valid FTP credentials and sends a crafted MKD request with a traversal sequence.
Description
Directory traversal vulnerability in the FTP server in Rhino Software Serv-U File Server 7.0.0.1 through 7.4.0.1 allows remote attackers to create arbitrary directories via a \.. (backslash dot dot) in an MKD request.
Exploits (1)
This exploit leverages a directory traversal vulnerability in FTP Serv-U via the MKD command, allowing an attacker to escape the FTP root and create arbitrary directories on the system. It requires valid FTP credentials and sends a crafted MKD request with a traversal sequence.