CVE-2022-22836

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
10/01/2022
Last modified:
19/01/2022

Description

CoreFTP Server before 727 allows directory traversal (for file creation) by an authenticated attacker via ../ in an HTTP PUT request.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:coreftp:core_ftp:*:*:*:*:*:*:*:* 1.2 (including)
cpe:2.3:a:coreftp:core_ftp:2.0:build_639:*:*:*:*:*:*
cpe:2.3:a:coreftp:core_ftp:2.0:build_640:*:*:*:*:*:*
cpe:2.3:a:coreftp:core_ftp:2.0:build_641:*:*:*:*:*:*
cpe:2.3:a:coreftp:core_ftp:2.0:build_642:*:*:*:*:*:*
cpe:2.3:a:coreftp:core_ftp:2.0:build_645:*:*:*:*:*:*
cpe:2.3:a:coreftp:core_ftp:2.0:build_647:*:*:*:*:*:*
cpe:2.3:a:coreftp:core_ftp:2.0:build_649:*:*:*:*:*:*
cpe:2.3:a:coreftp:core_ftp:2.0:build_651:*:*:*:*:*:*
cpe:2.3:a:coreftp:core_ftp:2.0:build_653:*:*:*:*:*:*
cpe:2.3:a:coreftp:core_ftp:2.0:build_655:*:*:*:*:*:*
cpe:2.3:a:coreftp:core_ftp:2.0:build_656:*:*:*:*:*:*
cpe:2.3:a:coreftp:core_ftp:2.0:build_657:*:*:*:*:*:*
cpe:2.3:a:coreftp:core_ftp:2.0:build_658:*:*:*:*:*:*
cpe:2.3:a:coreftp:core_ftp:2.0:build_659:*:*:*:*:*:*