ArGoSoft FTP Server before 1.4.2.7 allows remote attackers to read arbitrary files by uploading a ZIP file containing a shortcut (.LNK) file, using SITE UNZIP to extract the .LNK file onto the server, then accessing the file, a different vulnerability than CVE-2005-0520.
References
Configurations
Configuration 1 (hide)
|
History
20 Nov 2024, 23:55
Type | Values Removed | Values Added |
---|---|---|
References | () http://secunia.com/advisories/14172 - Patch | |
References | () http://www.argosoft.com/ftpserver/changelist.aspx - Patch, Vendor Advisory | |
References | () http://www.osvdb.org/13614 - | |
References | () http://www.securityfocus.com/bid/12487 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/17939 - |
Information
Published : 2005-02-18 05:00
Updated : 2024-11-20 23:55
NVD link : CVE-2005-0519
Mitre link : CVE-2005-0519
CVE.ORG link : CVE-2005-0519
JSON object : View
Products Affected
argosoft
- ftp_server
CWE