CVE-2001-0054

Directory traversal vulnerability in FTP Serv-U before 2.5i allows remote attackers to escape the FTP root and read arbitrary files by appending a string such as "/..%20." to a CD command, a variant of a .. (dot dot) attack.
Configurations

Configuration 1 (hide)

cpe:2.3:a:solarwinds:serv-u_file_server:3.0.0.16:*:*:*:*:*:*:*

History

No history.

Information

Published : 2001-02-16 05:00

Updated : 2023-12-10 10:17


NVD link : CVE-2001-0054

Mitre link : CVE-2001-0054

CVE.ORG link : CVE-2001-0054


JSON object : View

Products Affected

solarwinds

  • serv-u_file_server
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')