CVE
- Id
- 3740
- CVE No.
- CVE-2001-0934
- Status
- Candidate
- Description
- Cooolsoft PowerFTP Server 2.03 allows remote attackers to obtain the physical path of the server root via the pwd command, which lists the full pathname.
- Phase
- Proposed (20020131)
- Votes
- ACCEPT(1) Foat | MODIFY(1) Frech | NOOP(4) Armstrong, Christey, Cole, Wall
- Comments
- Frech> (ACCEPT; Task 2353) | Christey> Rediscovered in: | BUGTRAQ:20020211 PowerFTP Personal FTP Server Multiple Vulnerabilities | http://marc.theaimsgroup.com/?l=bugtraq&m=101361745222207&w=2 | This rediscovery says the problem is in 2.10. | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:powerftp-pwd-path-disclosure(8182) | Christey> BID:4072 | URL:http://online.securityfocus.com/bid/4072