search menu icon-carat-right cmu-wordmark

CERT Coordination Center

Netwin Surge FTP Server does not adequately validate user input thereby allowing directory traversal

Vulnerability Note VU#219043

Original Release Date: 2002-03-29 | Last Revised: 2004-02-23

Overview

Surge FTP Server 2.0a contains a directory traversal vulnerability.

Description

Surge FTP Server 2.0a allows remote users to list files outside the FTP root directory.

Impact

Attackers may list files from directories to which access was not granted.

Solution

Upgrade to version 2.0b, available at:

http://www.netwinsite.com/surgeftp

Vendor Information

219043
 

CVSS Metrics

Group Score Vector
Base
Temporal
Environmental

References

Acknowledgements

Thanks to Sentry Research Labs for reporting this vulnerability.

This document was written by Shawn Van Ittersum.

Other Information

CVE IDs: CVE-2001-0698
Severity Metric: 1.84
Date Public: 2001-06-19
Date First Published: 2002-03-29
Date Last Updated: 2004-02-23 22:07 UTC
Document Revision: 10

Sponsored by CISA.