CVE-2002-1345
published 2002-12-23CVE-2002-1345: Directory traversal vulnerabilities in multiple FTP clients on UNIX systems allow remote malicious FTP servers to create or overwrite files as the client user…
PriorityP416medium5CVSS 2.0
AVNACLAuNCNIPAN
EPSS
2.78%
84.7th percentile
Directory traversal vulnerabilities in multiple FTP clients on UNIX systems allow remote malicious FTP servers to create or overwrite files as the client user via filenames containing /absolute/path or .. (dot dot) sequences.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| core_ftp | core_ftp | — | — |
| estsoft | alftp | — | — |
| estsoft | alftp | — | — |
| fireftp | fireftp | <= 0.98 | — |
| globalscape | cuteftp | — | — |
| glub | secure_ftp | <= 2.5.15 | — |
| ncftp_software | ncftp | — | — |
| ncftp_software | ncftp | — | — |
| ncftp_software | ncftp | — | — |
| ncftp_software | ncftp | — | — |
| ncftp_software | ncftp | — | — |
| ncftp_software | ncftp | — | — |
| ncftp_software | ncftp | — | — |
| ncftp_software | ncftp | — | — |
| ncftp_software | ncftp | — | — |
| ncftp_software | ncftp | — | — |
| nch_software | nch_software_classic_ftp | — | — |
| openbsd | openbsd | — | — |
| sun | solaris | — | — |
| sun | solaris | — | — |
| sun | sunos | — | — |
| visicommedia | aceftp | — | — |
| wise-ftp | wise-ftp | — | — |
| wise-ftp | wise-ftp | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3mm4-jwgr-q6c5: Directory traversal vulnerability in the FTP client in AceFTP Freeware 3
ghsa_unreviewed·2022-05-17·CVSS 5.0
CVE-2008-5175 [MEDIUM] CWE-22 GHSA-3mm4-jwgr-q6c5: Directory traversal vulnerability in the FTP client in AceFTP Freeware 3
Directory traversal vulnerability in the FTP client in AceFTP Freeware 3.80.3 and AceFTP Pro 3.80.3 allows remote FTP servers to create or overwrite arbitrary files via a .. (dot dot) in a response to a LIST command, a related issue to CVE-2002-1345.
GHSA
GHSA-23mg-qphc-9fg5: Directory traversal vulnerabilities in multiple FTP clients on UNIX systems allow remote malicious FTP servers to create or overwrite files as the cli
ghsa_unreviewed·2022-05-03
CVE-2002-1345 [MEDIUM] GHSA-23mg-qphc-9fg5: Directory traversal vulnerabilities in multiple FTP clients on UNIX systems allow remote malicious FTP servers to create or overwrite files as the cli
Directory traversal vulnerabilities in multiple FTP clients on UNIX systems allow remote malicious FTP servers to create or overwrite files as the client user via filenames containing /absolute/path or .. (dot dot) sequences.
GHSA
GHSA-8q66-4pqj-jhjr: Directory traversal vulnerability in the FTP client in Glub Tech Secure FTP before 2
ghsa_unreviewed·2022-05-01·CVSS 5.0
CVE-2008-2821 [MEDIUM] CWE-22 GHSA-8q66-4pqj-jhjr: Directory traversal vulnerability in the FTP client in Glub Tech Secure FTP before 2
Directory traversal vulnerability in the FTP client in Glub Tech Secure FTP before 2.5.16 on Windows allows remote FTP servers to create or overwrite arbitrary files via a ..\ (dot dot backslash) in a response to a LIST command, a related issue to CVE-2002-1345.
GHSA
GHSA-22rg-5392-7gh6: Directory traversal vulnerability in the FTP client in ALTools ESTsoft ALFTP 4
ghsa_unreviewed·2022-05-01·CVSS 5.0
CVE-2008-2702 [MEDIUM] CWE-22 GHSA-22rg-5392-7gh6: Directory traversal vulnerability in the FTP client in ALTools ESTsoft ALFTP 4
Directory traversal vulnerability in the FTP client in ALTools ESTsoft ALFTP 4.1 beta 2 and 5.0 allows remote FTP servers to create or overwrite arbitrary files via a .. (dot dot) in a response to a LIST command, a related issue to CVE-2002-1345. NOTE: this can be leveraged for code execution by writing to a Startup folder.
GHSA
GHSA-6hxg-34v8-xgrp: Directory traversal vulnerability in the FireFTP add-on before 0
ghsa_unreviewed·2022-05-01·CVSS 5.0
CVE-2008-2399 [MEDIUM] CWE-22 GHSA-6hxg-34v8-xgrp: Directory traversal vulnerability in the FireFTP add-on before 0
Directory traversal vulnerability in the FireFTP add-on before 0.98.20080518 for Firefox allows remote FTP servers to create or overwrite arbitrary files via ..\ (dot dot backslash) sequences in responses to (1) MLSD and (2) LIST commands, a related issue to CVE-2002-1345. NOTE: this can be leveraged for code execution by writing to a Startup folder.
GHSA
GHSA-vmv8-824c-x53w: Directory traversal vulnerability in Core FTP client 2
ghsa_unreviewed·2022-05-01·CVSS 5.0
CVE-2008-2519 [MEDIUM] CWE-22 GHSA-vmv8-824c-x53w: Directory traversal vulnerability in Core FTP client 2
Directory traversal vulnerability in Core FTP client 2.1 Build 1565 allows remote FTP servers to create or overwrite arbitrary files via .. (dot dot) sequences in responses to LIST commands, a related issue to CVE-2002-1345. NOTE: this can be leveraged for code execution by writing to a Startup folder.
GHSA
GHSA-53cx-mxm9-g44r: Directory traversal vulnerability in GlobalSCAPE CuteFTP Home 8
ghsa_unreviewed·2022-05-01·CVSS 5.0
CVE-2008-2779 [MEDIUM] CWE-22 GHSA-53cx-mxm9-g44r: Directory traversal vulnerability in GlobalSCAPE CuteFTP Home 8
Directory traversal vulnerability in GlobalSCAPE CuteFTP Home 8.2.0 Build 02.26.2008.4 and CuteFTP Pro 8.2.0 Build 04.01.2008.1 allows remote FTP servers to create or overwrite arbitrary files via ..\ (dot dot backslash) sequences in responses to LIST commands, a related issue to CVE-2002-1345. NOTE: this can be leveraged for code execution by writing to a Startup folder.
GHSA
GHSA-ffhc-mxrh-vv2p: Directory traversal vulnerability in the FTP client in NCH Software Classic FTP 1
ghsa_unreviewed·2022-05-01·CVSS 5.0
CVE-2008-2894 [MEDIUM] CWE-22 GHSA-ffhc-mxrh-vv2p: Directory traversal vulnerability in the FTP client in NCH Software Classic FTP 1
Directory traversal vulnerability in the FTP client in NCH Software Classic FTP 1.02 for Windows allows remote FTP servers to create or overwrite arbitrary files via a .. (dot dot) in a response to a LIST command, a related issue to CVE-2002-1345.
GHSA
GHSA-99f8-xrvq-qw36: Directory traversal vulnerability in the FTP client in AceBIT WISE-FTP 4
ghsa_unreviewed·2022-05-01·CVSS 5.0
CVE-2008-2889 [MEDIUM] CWE-22 GHSA-99f8-xrvq-qw36: Directory traversal vulnerability in the FTP client in AceBIT WISE-FTP 4
Directory traversal vulnerability in the FTP client in AceBIT WISE-FTP 4.1.0 and 5.5.8 allows remote FTP servers to create or overwrite arbitrary files via a ..\ (dot dot backslash) in a response to a LIST command, a related issue to CVE-2002-1345.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
CWE
Improper Neutralization of Leading Special Elements
mitre_cwe
CWE-160 Improper Neutralization of Leading Special Elements
CWE-160: Improper Neutralization of Leading Special Elements
The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes leading special elements that could be interpreted in unexpected ways when they are sent to a downstream component.
As data is parsed, improperly handled leading special elements may cause the process to take unexpected actions that result in an attack.
Modes of Introduction:
Phase: Implementation
Common Consequences:
Scope: Integrity. Impact: Unexpected State.
Potential Mitigations:
Developers should anticipate that leading special elements will be injected/removed/manipulated in the input vectors of their product. Use an appropriate combination of denylists and allowlists to ensure only valid, expected and appropria
CWE
Absolute Path Traversal
mitre_cwe
CWE-36 Absolute Path Traversal
CWE-36: Absolute Path Traversal
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize absolute path sequences such as "/abs/path" that can resolve to a location that is outside of that directory.
This allows attackers to traverse the file system to access files or directories that are outside of the restricted directory.
Modes of Introduction:
Phase: Implementation
Common Consequences:
Scope: Integrity, Confidentiality, Availability. Impact: Execute Unauthorized Code or Commands. The attacker may be able to create or overwrite critical files that are used to execute code, such as programs or libraries.
Scope: Integrity. Impact: Modify Files or Directories. The attacker may be able to overwrite or create
CWE
Path Traversal: '/absolute/pathname/here'
mitre_cwe
CWE-37 Path Traversal: '/absolute/pathname/here'
CWE-37: Path Traversal: '/absolute/pathname/here'
The product accepts input in the form of a slash absolute path ('/absolute/pathname/here') without appropriate validation, which can allow an attacker to traverse the file system to unintended locations or access arbitrary files.
Modes of Introduction:
Phase: Implementation
Common Consequences:
Scope: Confidentiality, Integrity. Impact: Read Files or Directories, Modify Files or Directories.
Detection Methods:
Automated Static Analysis: Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searchin
ftp://patches.sgi.com/support/free/security/advisories/20021205-01-Ahttp://archives.neohapsis.com/archives/vulnwatch/2002-q4/0102.htmlhttp://marc.info/?l=bugtraq&m=103962838628940&w=2http://www.iss.net/security_center/static/10821.phphttp://www.kb.cert.org/vuls/id/210409http://www.securityfocus.com/bid/6360ftp://patches.sgi.com/support/free/security/advisories/20021205-01-Ahttp://archives.neohapsis.com/archives/vulnwatch/2002-q4/0102.htmlhttp://marc.info/?l=bugtraq&m=103962838628940&w=2http://www.iss.net/security_center/static/10821.phphttp://www.kb.cert.org/vuls/id/210409http://www.securityfocus.com/bid/6360
2002-12-23
Published