First published: Fri Feb 16 2001(Updated: )
Directory traversal vulnerability in FTP Serv-U before 2.5i allows remote attackers to escape the FTP root and read arbitrary files by appending a string such as "/..%20." to a CD command, a variant of a .. (dot dot) attack.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Solarwinds Serv-u File Server | =3.0.0.16 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-0054 is considered a high-severity vulnerability due to its potential to allow unauthorized access to sensitive files.
To fix CVE-2001-0054, upgrade to a version of Solarwinds Serv-U File Server that is patched against this vulnerability.
CVE-2001-0054 affects Solarwinds Serv-U File Server versions prior to 3.0.0.16.
CVE-2001-0054 involves a directory traversal attack that allows attackers to escape the FTP root.
Yes, CVE-2001-0054 can be exploited remotely by attackers using specially crafted FTP commands.