CVE
- Id
- 5366
- CVE No.
- CVE-2002-0978
- Status
- Candidate
- Description
- Microsoft File Transfer Manager (FTM) ActiveX control before 4.0 allows remote attackers to upload or download arbitrary files to arbitrary locations via a man-in-the-middle attack with modified TGT and TGN parameters in a call to the "Persist" function.
- Phase
- Proposed (20020830)
- Votes
- ACCEPT(2) Cole, LeBlanc | MODIFY(1) Frech | NOOP(4) Armstrong, Christey, Cox, Foat | REVIEWING(1) Wall
- Comments
- Christey> XF:ms-ftm-file-upload(9907) | URL:http://www.iss.net/security_center/static/9907.php | BID:5512 | URL:http://www.securityfocus.com/bid/5512 | | Discloser claimed bug was fixed, but I can"t find independent | acknowledgement from Microsoft. Inquiry sent to Microsoft on | November 18, 2002. They acknowledged, via email, that the | issue was fixed. | Frech> XF:ms-ftm-file-upload(9907)