FTP.NLST.Directory.Traversal

Alias/esCooolSoft.PowerFTP.NLST.Directory.Traversal
Release DateAug 09, 2005
SeverityHigh
ImpactInformation disclosure.
DescriptionIt indicates a possible exploit of Directory Traversal Vulnerability in CoolSoft PowerFTP that may allow a remote attackers to list or read arbitrary files and directories via a .. (dot dot) in ls and get commands.
Affected ProductsCooolsoft PowerFTP 2.24 and earlier versions.
Recommended ActionsUpgrade Coolsoft PowerFTP later than 2.24.
Common Vulnerabilities and Exposures (CVE)http://cve.mitre.org/cgi-bin/cvename.cgi?name=2001-0931
Reference/shttp://www.securityfocus.com/bid/3593 (BugTraq)
Reference: VID-10462