CVE
- Id
- 3395
- CVE No.
- CVE-2001-0582
- Status
- Candidate
- Description
- Ben Spink CrushFTP FTP Server 2.1.6 and earlier allows a local attacker to access arbitrary files via a ".." (dot dot) attack, or variations, in (1) GET, (2) CD, (3) NLST, (4) SIZE, (5) RETR.
- Phase
- Modified (20050510)
- Votes
- ACCEPT(4) Bishop, Cole, Frech, Ziese | NOOP(2) Foat, Wall
- Comments