Multiple directory traversal vulnerabilities in SeleniumServer FTP Server 1.0, and possibly earlier, allow remote attackers to list arbitrary directories, read arbitrary files, and upload arbitrary files via directory traversal sequences in the (1) DIR (LIST or NLST), (2) GET (RETR), and (3) PUT (STOR) commands.
References
Configurations
History
21 Nov 2024, 00:21
Type | Values Removed | Values Added |
---|---|---|
References | () http://secunia.com/advisories/22928 - Vendor Advisory | |
References | () http://whitestar.linuxbox.org/pipermail/exploits/2006-November/000037.html - | |
References | () http://www.osvdb.org/30448 - | |
References | () http://www.vupen.com/english/advisories/2006/4540 - Vendor Advisory | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/30332 - |
Information
Published : 2006-11-20 21:07
Updated : 2024-11-21 00:21
NVD link : CVE-2006-5981
Mitre link : CVE-2006-5981
CVE.ORG link : CVE-2006-5981
JSON object : View
Products Affected
biba_software
- seleniumserver_ftp_server
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')