First published: Fri Oct 21 2005(Updated: )
The FTP client in Windows XP SP1 and Server 2003, and Internet Explorer 6 SP1 on Windows 2000 SP4, when "Enable Folder View for FTP Sites" is enabled and the user manually initiates a file transfer, allows user-assisted, remote FTP servers to overwrite files in arbitrary locations via crafted filenames.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Internet Explorer | =6.0-sp1 | |
Microsoft Windows XP | =sp1 | |
Microsoft Windows 2003 Server | =r2 | |
Microsoft Windows 2000 | =sp4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-2126 is considered a medium severity vulnerability.
To fix CVE-2005-2126, users should disable the 'Enable Folder View for FTP Sites' option.
CVE-2005-2126 affects Microsoft Internet Explorer 6.0 SP1, Windows XP SP1, Windows 2003 Server, and Windows 2000 SP4.
CVE-2005-2126 does not provide remote access, but it can be exploited by remote FTP servers to overwrite files.
CVE-2005-2126 is a file overwrite vulnerability that requires user-assisted actions to exploit.