CVE-2001-0054: Path Traversal
Published Feb 16, 2001
·Updated
Directory traversal vulnerability in FTP Serv-U before 2.5i allows remote attackers to escape the FTP root and read arbitrary files by appending a string such as "/..%20." to a CD command, a variant of a .. (dot dot) attack.
Affected Software
1 affected component
SolarWinds Serv-u File Server=3.0.0.16
Remediation
Patch Available
Event History
Feb 16, 2001
CVE Published
05:00 AM
May 7, 2001
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-0054?
CVE-2001-0054 is considered a high-severity vulnerability due to its potential to allow unauthorized access to sensitive files.
2
How do I fix CVE-2001-0054?
To fix CVE-2001-0054, upgrade to a version of Solarwinds Serv-U File Server that is patched against this vulnerability.
3
Which versions of Solarwinds Serv-U File Server are affected by CVE-2001-0054?
CVE-2001-0054 affects Solarwinds Serv-U File Server versions prior to 3.0.0.16.
4
What type of attack does CVE-2001-0054 involve?
CVE-2001-0054 involves a directory traversal attack that allows attackers to escape the FTP root.
5
Can CVE-2001-0054 be exploited remotely?
Yes, CVE-2001-0054 can be exploited remotely by attackers using specially crafted FTP commands.