CVE-2019-9648

MEDIUM

Core FTP <2.0 Build 674 - Path Traversal

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2019-9648. PoCs published by Kevin Randall, KevinRandall1337.

AI-analyzed exploit summary This exploit leverages a directory traversal vulnerability in CoreFTP Server via the SIZE command to check for the existence of arbitrary files on the remote system. It connects to the FTP server, authenticates anonymously, and attempts to traverse directories to locate a specified file (e.g., nslookup.exe).

Description

An issue was discovered in the SFTP Server component in Core FTP 2.0 Build 674. A directory traversal vulnerability exists using the SIZE command along with a \..\..\ substring, allowing an attacker to enumerate file existence based on the returned information.

Exploits (2)

exploitdb WORKING POC
by Kevin Randall · textdoswindows
https://www.exploit-db.com/exploits/46535

This exploit leverages a directory traversal vulnerability in CoreFTP Server via the SIZE command to check for the existence of arbitrary files on the remote system. It connects to the FTP server, authenticates anonymously, and attempts to traverse directories to locate a specified file (e.g., nslookup.exe).

Classification
Working Poc 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: CoreFTP Server FTP / SFTP Server v2 - Build 674
Auth required
Prerequisites: Network access to the FTP server · Anonymous authentication enabled
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/107446
Product, Vendor Advisory x_refsource_confirm
http://www.coreftp.com/forums/viewtopic.php?f=15&t=4022509
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/46535
Exploit, Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
https://seclists.org/fulldisclosure/2019/Mar/23
Mailing List mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2019/Aug/21

Scores

CVSS v3 5.3
EPSS 0.1973
EPSS Percentile 95.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-22
Status published
Products (2)
coreftp/core_ftp 2.0
nuget/CoreFtp 0NuGet
Published Mar 22, 2019
Tracked Since Feb 18, 2026