Lucene search

K
nvd[email protected]NVD:CVE-2008-2779
HistoryJun 19, 2008 - 8:41 p.m.

CVE-2008-2779

2008-06-1920:41:00
CWE-22
web.nvd.nist.gov
4

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7

Confidence

Low

EPSS

0.002

Percentile

57.1%

Directory traversal vulnerability in GlobalSCAPE CuteFTP Home 8.2.0 Build 02.26.2008.4 and CuteFTP Pro 8.2.0 Build 04.01.2008.1 allows remote FTP servers to create or overwrite arbitrary files via …\ (dot dot backslash) sequences in responses to LIST commands, a related issue to CVE-2002-1345. NOTE: this can be leveraged for code execution by writing to a Startup folder.

Affected configurations

Nvd
Node
globalscapecuteftpMatch8.2.0home
OR
globalscapecuteftpMatch8.2.0pro
VendorProductVersionCPE
globalscapecuteftp8.2.0cpe:2.3:a:globalscape:cuteftp:8.2.0:*:home:*:*:*:*:*
globalscapecuteftp8.2.0cpe:2.3:a:globalscape:cuteftp:8.2.0:*:pro:*:*:*:*:*

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7

Confidence

Low

EPSS

0.002

Percentile

57.1%

Related for NVD:CVE-2008-2779