header-logo
Suggest Exploit
vendor:
Baby FTP Server
by:
4.3
CVSS
MEDIUM
Directory Traversal
22
CWE
Product Name: Baby FTP Server
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE: CVE-2003-0282
CPE: a:reiyo:ftpserv:1.2.0
Metasploit:
Other Scripts:
Platforms Tested: Windows
2003

Baby FTP Server Directory Traversal Vulnerability

Baby FTP Server does not properly handle some types of requests, allowing a remote user to gain access to resources outside of the FTP root directory.

Mitigation:

Upgrade to a patched version of the software or use an alternative FTP server.
Source

Exploit-DB raw data:

source: https://www.securityfocus.com/bid/7749/info

It has been reported that Baby FTP Server does not properly handle some types of requests. This may make it possible for a remote user to gain access to resources outside of the FTP root directory. 

CWD ...
CWD /...
CWD /......
CWD \...
CWD ...CWD .../