CVE-2010-2695

Directory traversal vulnerability in the SFTP/SSH2 virtual server in Xlight FTP Server 3.5.0, 3.5.5, and possibly other versions before 3.6 allows remote authenticated users to read, overwrite, or delete arbitrary files via .. (dot dot) sequences in the (1) ls, (2) rm, (3) rename, and other unspecified commands.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:xlightftpd:xlight_ftp_server:3.5:*:*:*:*:*:*:*
cpe:2.3:a:xlightftpd:xlight_ftp_server:3.5.5:*:*:*:*:*:*:*

History

21 Nov 2024, 01:17

Type Values Removed Values Added
References () http://osvdb.org/66037 - () http://osvdb.org/66037 -
References () http://secunia.com/advisories/40473 - Vendor Advisory () http://secunia.com/advisories/40473 - Vendor Advisory
References () http://www.securityfocus.com/archive/1/512192/100/0/threaded - () http://www.securityfocus.com/archive/1/512192/100/0/threaded -
References () http://www.xlightftpd.com/whatsnew.htm - Patch () http://www.xlightftpd.com/whatsnew.htm - Patch
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/60151 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/60151 -

Information

Published : 2010-07-12 17:30

Updated : 2024-11-21 01:17


NVD link : CVE-2010-2695

Mitre link : CVE-2010-2695

CVE.ORG link : CVE-2010-2695


JSON object : View

Products Affected

xlightftpd

  • xlight_ftp_server
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')