Show filters
17 Total Results
Displaying 1-10 of 17
Sort by:
Attacker Value
Unknown
CVE-2018-10916
Disclosure Date: August 01, 2018 (last updated November 27, 2024)
It has been discovered that lftp up to and including version 4.8.3 does not properly sanitize remote file names, leading to a loss of integrity on the local system when reverse mirroring is used. A remote attacker may trick a user to use reverse mirroring on an attacker controlled FTP server, resulting in the removal of all files in the current working directory of the victim's system.
1
Attacker Value
Unknown
CVE-2010-2251
Disclosure Date: July 06, 2010 (last updated October 04, 2023)
The get1 command, as used by lftpget, in LFTP before 4.0.6 does not properly validate a server-provided filename before determining the destination filename of a download, which allows remote servers to create or overwrite arbitrary files via a Content-Disposition header that suggests a crafted filename, and possibly execute arbitrary code as a consequence of writing to a dotfile in a home directory.
1
Attacker Value
Unknown
CVE-2007-2348
Disclosure Date: April 27, 2007 (last updated November 08, 2023)
mirror --script in lftp before 3.5.9 does not properly quote shell metacharacters, which might allow remote user-assisted attackers to execute shell commands via a malicious script. NOTE: it is not clear whether this issue crosses security boundaries, since the script already supports commands such as "get" which could overwrite executable files.
1
Attacker Value
Unknown
CVE-2021-31645
Disclosure Date: July 07, 2022 (last updated October 07, 2023)
An issue was discovered in glFTPd 2.11a that allows remote attackers to cause a denial of service via exceeding the connection limit.
0
Attacker Value
Unknown
CVE-2012-0315
Disclosure Date: February 22, 2012 (last updated October 04, 2023)
Untrusted search path vulnerability in ALFTP before 5.31 allows local users to gain privileges via a Trojan horse executable file in a directory that is accessed for reading an extensionless file, as demonstrated by executing the README.exe file when a user attempts to access the README file.
0
Attacker Value
Unknown
CVE-2008-2702
Disclosure Date: June 13, 2008 (last updated October 04, 2023)
Directory traversal vulnerability in the FTP client in ALTools ESTsoft ALFTP 4.1 beta 2 and 5.0 allows remote FTP servers to create or overwrite arbitrary files via a .. (dot dot) in a response to a LIST command, a related issue to CVE-2002-1345. NOTE: this can be leveraged for code execution by writing to a Startup folder.
0
Attacker Value
Unknown
CVE-2006-5949
Disclosure Date: November 17, 2006 (last updated October 04, 2023)
Directory traversal vulnerability in ALTools ALFTP FTP Server 4.1 beta 1, and possibly earlier, allows remote attackers to create arbitrary directories via directory traversal sequences in a MKD request. NOTE: the provenance of this information is unknown; details are obtained from third party sources.
0
Attacker Value
Unknown
CVE-2006-5950
Disclosure Date: November 17, 2006 (last updated October 04, 2023)
Unspecified vulnerability in ALTools ALFTP FTP Server 4.1 beta 1, and possibly earlier, allows remote authenticated users to obtain the installation path via unknown vectors related to the REN command, probably due to response messages. NOTE: the provenance of this information is unknown; details are obtained from third party sources.
0
Attacker Value
Unknown
CVE-2006-1253
Disclosure Date: March 19, 2006 (last updated October 04, 2023)
Unspecified vulnerability in glFTPd before 2.01 RC5 allows remote attackers to bypass IP checks via a crafted DNS hostname, possibly a hostname that appears to be an IP address.
0
Attacker Value
Unknown
CVE-2005-0483
Disclosure Date: March 30, 2005 (last updated October 04, 2023)
Multiple directory traversal vulnerabilities in sitenfo.sh, sitezipchk.sh, and siteziplist.sh in Glftpd 1.26 to 2.00 allow remote authenticated users to (1) determine the existence of arbitrary files, (2) list files in restricted directories, or (3) read arbitrary files from within ZIP or gzip files, via .. (dot dot) sequences and globbing ("*") characters in a SITE NFO command.
0