Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
Unknown

CVE-2010-5219

Disclosure Date: September 06, 2012 (last updated October 05, 2023)
Untrusted search path vulnerability in SmartFTP 4.0.1140.0 allows local users to gain privileges via a Trojan horse dwmapi.dll file in the current working directory, as demonstrated by a directory that contains a .txt, .html, or .mpg file. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2010-4871

Disclosure Date: October 07, 2011 (last updated October 04, 2023)
Unspecified vulnerability in SmartFTP before 4.0 Build 1142 allows attackers to have an unknown impact via a long filename.
0
Attacker Value
Unknown

CVE-2010-3099

Disclosure Date: August 20, 2010 (last updated October 04, 2023)
Directory traversal vulnerability in SmartSoft Ltd SmartFTP Client 4.0.1124.0, and possibly other versions before 4.0 Build 1133, allows remote FTP servers to overwrite arbitrary files via a "..\" (dot dot backslash) in a filename. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2007-0790

Disclosure Date: February 06, 2007 (last updated October 04, 2023)
Heap-based buffer overflow in SmartFTP 2.0.1002 allows remote FTP servers to execute arbitrary code via a large banner.
0
Attacker Value
Unknown

CVE-2003-1319

Disclosure Date: December 31, 2003 (last updated February 22, 2025)
Multiple buffer overflows in SmartFTP 1.0.973, and other versions before 1.0.976, allow remote attackers to execute arbitrary code via (1) a long response to a PWD command, which triggers a stack-based overflow, and (2) a long line in a response to a file LIST command, which triggers a heap-based overflow.
0
Attacker Value
Unknown

CVE-2000-0565

Disclosure Date: June 13, 2000 (last updated February 22, 2025)
SmartFTP Daemon 0.2 allows a local user to access arbitrary files by uploading and specifying an alternate user configuration file via a .. (dot dot) attack.
0