TROYANOSYVIRUS
Voltar para CVEs

CVE-2008-5275

N/A

Descricao

Multiple directory traversal vulnerabilities in the (a) "Unzip archive" and (b) "Upload files and archives" functionality in net2ftp 0.96 stable and 0.97 beta allow remote attackers to create, read, or delete arbitrary files via a .. (dot dot) in a filename within a (1) TAR or (2) ZIP archive. NOTE: this can be leveraged for code execution by creating a .php file.

Detalhes CVE

Pontuacao CVSS v3.1N/A
Publicado11/28/2008
Ultima modificacao4/23/2026
Fontenvd
Avistamentos honeypot0

Produtos afetados

net2ftp:net2ftp

Fraquezas (CWE)

CWE-22

Referencias

Correlacoes IOC

Sem correlacoes registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.