Vulnerabilities > CVE-2005-1484 - Directory Traversal vulnerability in Golden FTP Server Pro

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
kmint21-software
nessus

Summary

Directory traversal vulnerability in Golden FTP server pro 2.52 allows remote attackers to read arbitrary files via a "\.." (backward slash dot dot) with a leading '"' (double quote) in the GET command.

Nessus

NASL familyFTP
NASL idGOLDEN_FTP_SERVER_TRAVERSAL.NASL
descriptionThe version of Golden FTP Server installed on the remote host is prone to a directory traversal attack. Specifically, an attacker can read files located outside a share with
last seen2020-06-01
modified2020-06-02
plugin id18194
published2005-05-04
reporterThis script is Copyright (C) 2005-2018 and is owned by Tenable, Inc. or an Affiliate thereof.
sourcehttps://www.tenable.com/plugins/nessus/18194
titleGolden FTP Server Pro GET Traversal Arbitrary File Access