vendor:
CoreFTP Server FTP / SFTP Server
by:
Kevin Randall
5.3
CVSS
MEDIUM
Directory Traversal
22
CWE
Product Name: CoreFTP Server FTP / SFTP Server
Affected Version From: v2 - Build 674
Affected Version To: v2 - Build 674
Patch Exists: YES
Related CWE: CVE-2019-9648
CPE: a:coreftp:coreftp_server_ftp/sftp_server
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 7
2019
CoreFTP Server FTP / SFTP Server v2 – Build 674 SIZE Directory Traversal
CoreFTP Server FTP / SFTP Server v2 - Build 674 is vulnerable to a directory traversal attack when sending a SIZE command with a specially crafted path. An attacker can use this vulnerability to read files outside of the web root directory.
Mitigation:
Upgrade to the latest version of CoreFTP Server FTP / SFTP Server v2 - Build 674 or later.