CVE-2010-3097

Directory traversal vulnerability in WinFrigate Frigate 3 FTP client 3.36 and earlier allows remote FTP servers to overwrite arbitrary files via a "..\" (dot dot backslash) in a filename.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:winfrigate:frigate_3:*:*:*:*:*:*:*:*
cpe:2.3:a:winfrigate:frigate_3:3.17:*:*:*:*:*:*:*
cpe:2.3:a:winfrigate:frigate_3:3.18:*:*:*:*:*:*:*
cpe:2.3:a:winfrigate:frigate_3:3.19:*:*:*:*:*:*:*
cpe:2.3:a:winfrigate:frigate_3:3.20:*:*:*:*:*:*:*
cpe:2.3:a:winfrigate:frigate_3:3.21:*:*:*:*:*:*:*
cpe:2.3:a:winfrigate:frigate_3:3.22:*:*:*:*:*:*:*
cpe:2.3:a:winfrigate:frigate_3:3.23:*:*:*:*:*:*:*
cpe:2.3:a:winfrigate:frigate_3:3.24:*:*:*:*:*:*:*
cpe:2.3:a:winfrigate:frigate_3:3.25:*:*:*:*:*:*:*
cpe:2.3:a:winfrigate:frigate_3:3.26:*:*:*:*:*:*:*
cpe:2.3:a:winfrigate:frigate_3:3.27:*:*:*:*:*:*:*
cpe:2.3:a:winfrigate:frigate_3:3.28:*:*:*:*:*:*:*
cpe:2.3:a:winfrigate:frigate_3:3.29:*:*:*:*:*:*:*
cpe:2.3:a:winfrigate:frigate_3:3.30:*:*:*:*:*:*:*
cpe:2.3:a:winfrigate:frigate_3:3.31:*:*:*:*:*:*:*
cpe:2.3:a:winfrigate:frigate_3:3.32:*:*:*:*:*:*:*
cpe:2.3:a:winfrigate:frigate_3:3.33:*:*:*:*:*:*:*
cpe:2.3:a:winfrigate:frigate_3:3.34:*:*:*:*:*:*:*
cpe:2.3:a:winfrigate:frigate_3:3.35:*:*:*:*:*:*:*

History

21 Nov 2024, 01:18

Type Values Removed Values Added
References () http://secunia.com/advisories/40898 - Vendor Advisory () http://secunia.com/advisories/40898 - Vendor Advisory
References () http://www.htbridge.ch/advisory/directory_traversal_in_frigate_3_built_in_ftp_client.html - () http://www.htbridge.ch/advisory/directory_traversal_in_frigate_3_built_in_ftp_client.html -

Information

Published : 2010-08-20 20:00

Updated : 2024-11-21 01:18


NVD link : CVE-2010-3097

Mitre link : CVE-2010-3097

CVE.ORG link : CVE-2010-3097


JSON object : View

Products Affected

winfrigate

  • frigate_3
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')