Vulnerability Description
Directory traversal vulnerability in Cerberus FTP Server 1.5 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the CD command.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Grant Averett | Cerberus Ftp Server | <= 1.5 |
References
- http://www.greenepa.net/~averett/cerberus-releasenotes.htm#ReleaseNotes
- http://www.iss.net/security_center/static/7004.phpVendor Advisory
- http://www.securiteam.com/windowsntfocus/5SP0M0055W.html
- http://www.greenepa.net/~averett/cerberus-releasenotes.htm#ReleaseNotes
- http://www.iss.net/security_center/static/7004.phpVendor Advisory
- http://www.securiteam.com/windowsntfocus/5SP0M0055W.html
FAQ
What is CVE-2001-1295?
CVE-2001-1295 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Directory traversal vulnerability in Cerberus FTP Server 1.5 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the CD command.
How severe is CVE-2001-1295?
CVE-2001-1295 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2001-1295?
Check the references section above for vendor advisories and patch information. Affected products include: Grant Averett Cerberus Ftp Server.