CVE

Id
3395  
CVE No.
CVE-2001-0582  
Status
Candidate  
Description
Ben Spink CrushFTP FTP Server 2.1.6 and earlier allows a local attacker to access arbitrary files via a ".." (dot dot) attack, or variations, in (1) GET, (2) CD, (3) NLST, (4) SIZE, (5) RETR.  
Phase
Modified (20050510)  
Votes
ACCEPT(4) Bishop, Cole, Frech, Ziese | NOOP(2) Foat, Wall  
Comments