CVE-2011-4717

zFTPServer Suite 6.0.0.52 - Authenticated Path Traversal via RMD Command

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2011-4717. PoCs published by Stefan Schurtz.

AI-analyzed exploit summary This exploit leverages a directory traversal vulnerability in zFTPServer Suite 6.0.0.52 via the 'rmdir' command. It constructs a payload of '....//' sequences to traverse directories and attempts to delete a directory outside the intended scope.

Description

Directory traversal vulnerability in zFTPServer Suite 6.0.0.52 allows remote authenticated users to delete arbitrary directories via a crafted RMD (aka rmdir) command.

Exploits (1)

exploitdb WORKING POC
by Stefan Schurtz · perlremotewindows
https://www.exploit-db.com/exploits/18235

This exploit leverages a directory traversal vulnerability in zFTPServer Suite 6.0.0.52 via the 'rmdir' command. It constructs a payload of '....//' sequences to traverse directories and attempts to delete a directory outside the intended scope.

Classification
Working Poc 95%
Attack Type
Other
Complexity
Trivial
Reliability
Reliable
Target: zFTPServer Suite 6.0.0.52
Auth required
Prerequisites: Network access to the FTP server · Valid credentials (anonymous in this case)
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Various Sources x_refsource_confirm
http://forum.zftpserver.com/viewtopic.php?f=4&t=2927

Scores

EPSS 0.0114
EPSS Percentile 78.9%

Details

CWE
CWE-22
Status published
Products (1)
zftpserver/zftpserver_suite 6.0.0.52
Published Dec 20, 2011
Tracked Since Feb 18, 2026