Directory traversal vulnerability in Baby FTP Server 1.2, and possibly other versions before May 31, 2003 allows remote authenticated users to list arbitrary directories and possibly read files via "..." (triple dot) manipulations to the CWD command.
References
Configurations
History
20 Nov 2024, 23:46
Type | Values Removed | Values Added |
---|---|---|
References | () http://packetstormsecurity.org/0305-exploits/baby.txt - Exploit | |
References | () http://www.osvdb.org/24538 - | |
References | () http://www.pablosoftwaresolutions.com/html/baby_ftp_server.html - Patch | |
References | () http://www.securityfocus.com/bid/7749 - |
Information
Published : 2003-12-31 05:00
Updated : 2024-11-20 23:46
NVD link : CVE-2003-1299
Mitre link : CVE-2003-1299
CVE.ORG link : CVE-2003-1299
JSON object : View
Products Affected
pablo_software_solutions
- baby_ftp_server
CWE