PT-2010-4217 · Xlight · Xlight Ftp Server

CVE-2010-2695

·

Publicado

2010-07-12

·

Atualizado

2018-10-10

CVSS v2.0

6.5

Média

VetorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Xlight FTP Server versions 3.5.0 through 3.5.5
Description The issue allows remote authenticated users to read, overwrite, or delete arbitrary files via .. (dot dot) sequences in commands such as ls, rm, and rename.
Recommendations For versions 3.5.0 through 3.5.5, update to version 3.6 or later to resolve the issue.

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-2695

Produtos afetados

Xlight Ftp Server