First published: Thu May 24 2001(Updated: )
Directory traversal vulnerability in RaidenFTPD Server 2.1 before build 952 allows attackers to access files outside the ftp root via dot dot attacks, such as (1) .... in CWD, (2) .. in NLST, or (3) ... in NLST.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
RaidenFTPD | =2.1_build_947 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-0491 is considered to have moderate severity due to the potential for attackers to access sensitive files.
To fix CVE-2001-0491, upgrade to RaidenFTPD version 2.1 build 952 or later.
CVE-2001-0491 is associated with directory traversal attacks using dot dot sequences in commands like CWD and NLST.
CVE-2001-0491 specifically affects RaidenFTPD Server version 2.1 build 947 and earlier.
Yes, CVE-2001-0491 can allow attackers to access files outside of the FTP root, potentially exposing sensitive information.