Vulnerabilities > CVE-2004-2487

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN
exploit available

Summary

Directory traversal vulnerability in Nexgen FTP Server before 2.2.3.23 allows remote authenticated users to read or list arbitrary files via (1) "..", (2) "\..\" (backslash dot dot), or (3) "/../" sequences in (a) RETR (get), (b) NLST (ls), (c) LIST (ls), (d) RNFR, or (e) RNTO FTP commands.

Exploit-Db

descriptionNexGen FTP Server 1.0/2.x Remote Directory Traversal Vulnerability. CVE-2004-2487. Remote exploit for windows platform
idEDB-ID:23877
last seen2016-02-02
modified2004-03-24
published2004-03-24
reporterZiv Kamir
sourcehttps://www.exploit-db.com/download/23877/
titleNexGen FTP Server 1.0/2.x - Remote Directory Traversal Vulnerability