CVE-2019-10009

MEDIUM

Titan FTP Server 2019 Build 3505 - Path Traversal

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2019-10009. PoCs published by Kevin Randall, KevinRandall1337.

AI-analyzed exploit summary This exploit demonstrates a directory traversal vulnerability in Titan FTP Server 2019 Build 3505 via the PreviewHandler.ashx endpoint, allowing authenticated users to read arbitrary files outside the root directory using path traversal techniques.

Description

A Directory Traversal issue was discovered in the Web GUI in Titan FTP Server 2019 Build 3505. When an authenticated user attempts to preview an uploaded file (through PreviewHandler.ashx) by using a \..\..\ technique, arbitrary files can be loaded in the server response outside the root directory.

Exploits (2)

exploitdb WORKING POC
by Kevin Randall · textwebappswindows
https://www.exploit-db.com/exploits/46611

This exploit demonstrates a directory traversal vulnerability in Titan FTP Server 2019 Build 3505 via the PreviewHandler.ashx endpoint, allowing authenticated users to read arbitrary files outside the root directory using path traversal techniques.

Classification
Working Poc 100%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Titan FTP Server Version 2019 Build 3505
Auth required
Prerequisites: Authenticated access to Titan FTP Web GUI · BurpSuite or similar intercepting proxy
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Mailing List mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2019/Mar/47
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/46611/
Exploit, Mailing List, Third Party Advisory x_refsource_misc
https://seclists.org/fulldisclosure/2019/Mar/47
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/46611

Scores

CVSS v3 6.5
EPSS 0.1147
EPSS Percentile 95.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-22
Status published
Products (1)
southrivertech/titan_ftp_server 2019 3505
Published Jun 03, 2019
Tracked Since Feb 18, 2026