HIGH · 9.3

CVE-2008-2399

Directory traversal vulnerability in the FireFTP add-on before 0.98.20080518 for Firefox allows remote FTP servers to create or overwrite arbitrary files via ..\ (dot dot backslash) sequences in respo...

Vulnerability Description

Directory traversal vulnerability in the FireFTP add-on before 0.98.20080518 for Firefox allows remote FTP servers to create or overwrite arbitrary files via ..\ (dot dot backslash) sequences in responses to (1) MLSD and (2) LIST commands, a related issue to CVE-2002-1345. NOTE: this can be leveraged for code execution by writing to a Startup folder.

CVSS Score

9.3

HIGH

AV:N/AC:M/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
FireftpFireftp<= 0.98
MozillaFirefoxAll versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2008-2399?

CVE-2008-2399 is a vulnerability with a CVSS score of 9.3 (HIGH). Directory traversal vulnerability in the FireFTP add-on before 0.98.20080518 for Firefox allows remote FTP servers to create or overwrite arbitrary files via ..\ (dot dot backslash) sequences in respo...

How severe is CVE-2008-2399?

CVE-2008-2399 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2008-2399?

Check the references section above for vendor advisories and patch information. Affected products include: Fireftp Fireftp, Mozilla Firefox.