Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2008-5275

Опубликовано: 28 нояб. 2008
Источник: nvd
CVSS2: 7.5
EPSS Низкий

Описание

Multiple directory traversal vulnerabilities in the (a) "Unzip archive" and (b) "Upload files and archives" functionality in net2ftp 0.96 stable and 0.97 beta allow remote attackers to create, read, or delete arbitrary files via a .. (dot dot) in a filename within a (1) TAR or (2) ZIP archive. NOTE: this can be leveraged for code execution by creating a .php file.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:net2ftp:net2ftp:0.96:stable:*:*:*:*:*:*
cpe:2.3:a:net2ftp:net2ftp:0.97:beta:*:*:*:*:*:*

EPSS

Процентиль: 62%
0.0043
Низкий

7.5 High

CVSS2

Дефекты

CWE-22

Связанные уязвимости

github
больше 3 лет назад

Multiple directory traversal vulnerabilities in the (a) "Unzip archive" and (b) "Upload files and archives" functionality in net2ftp 0.96 stable and 0.97 beta allow remote attackers to create, read, or delete arbitrary files via a .. (dot dot) in a filename within a (1) TAR or (2) ZIP archive. NOTE: this can be leveraged for code execution by creating a .php file.

EPSS

Процентиль: 62%
0.0043
Низкий

7.5 High

CVSS2

Дефекты

CWE-22