Overview
SpoonFTP Server does not adequately validate user input, allowing directory traversal.
Description
SpoonFTP Server does not adequately validate arguments to the CWD command, allowing directory traversal out of the FTP root directory. |
Impact
Users may read any directory or file on the server with privileges of the user's FTP account. |
Solution
Upgrade Upgrade to version 1.01 of SpoonFTP: |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
Thanks to Joe Testa for reporting this vulnerability.
This document was written by Shawn Van Ittersum.
Other Information
CVE IDs: | CVE-2001-0963 |
Severity Metric: | 1.80 |
Date Public: | 2001-09-20 |
Date First Published: | 2002-09-26 |
Date Last Updated: | 2002-09-26 22:04 UTC |
Document Revision: | 4 |