CVE-2019-9649

MEDIUM

Core FTP <2.0 Build 674 - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2019-9649. PoCs published by Kevin Randall, KevinRandall1337.

AI-analyzed exploit summary This exploit demonstrates a directory traversal vulnerability in CoreFTP Server using the MDTM command to leak file metadata (modification time) of files outside the restricted directory. The PoC confirms the vulnerability by querying the modification time of a system file (ARP.exe).

Description

An issue was discovered in the SFTP Server component in Core FTP 2.0 Build 674. Using the MDTM FTP command, a remote attacker can use a directory traversal technique (..\..\) to browse outside the root directory to determine the existence of a file on the operating system, and its last modified date.

Exploits (2)

exploitdb WORKING POC
by Kevin Randall · textdoswindows
https://www.exploit-db.com/exploits/46534

This exploit demonstrates a directory traversal vulnerability in CoreFTP Server using the MDTM command to leak file metadata (modification time) of files outside the restricted directory. The PoC confirms the vulnerability by querying the modification time of a system file (ARP.exe).

Classification
Working Poc 100%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: CoreFTP Server FTP / SFTP Server v2 - Build 674
Auth required
Prerequisites: FTP access with valid credentials · CoreFTP Server v2 Build 674
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/107449
Product, Vendor Advisory x_refsource_confirm
http://www.coreftp.com/forums/viewtopic.php?f=15&t=4022509
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/46534
Exploit, Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
https://seclists.org/fulldisclosure/2019/Mar/25
Mailing List mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2019/Aug/22

Scores

CVSS v3 5.3
EPSS 0.1454
EPSS Percentile 96.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-22
Status published
Products (1)
coreftp/core_ftp 2.0
Published Mar 22, 2019
Tracked Since Feb 18, 2026