CVE
- Id
- 3115
- CVE No.
- CVE-2001-0294
- Status
- Candidate
- Description
- Directory traversal vulnerability in TYPSoft FTP Server 0.85 allows remote attackers to read arbitrary files via (1) a .. (dot dot) in a GET command, or (2) a ... in a CWD command.
- Phase
- Proposed (20010404)
- Votes
- MODIFY(1) Frech | NOOP(3) Cole, Wall, Ziese | REVIEWING(2) Bishop, Christey
- Comments
- Frech> XF:typsoft-ftp-directory-traversal(6165) | Christey> BID:2489 | | The CWD... may have been rediscovered for version 0.95 in: | BUGTRAQ:20010507 Vulnerabilty in TYPsoft FTP server | URL:http://online.securityfocus.com/archive/1/183917 | | However, this CWD uses ".../" whereas the initial post | used just "..." and said that the vendor had fixed the issue. | So, this is probably just an incomplete fix by the vendor.