CVE-2019-9649

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
22/03/2019
Last modified:
26/08/2019

Description

An issue was discovered in the SFTP Server component in Core FTP 2.0 Build 674. Using the MDTM FTP command, a remote attacker can use a directory traversal technique (..\..\) to browse outside the root directory to determine the existence of a file on the operating system, and its last modified date.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:coreftp:core_ftp:2.0:*:*:*:*:*:*:*