CVE-2008-1564: Path Traversal
Published Mar 31, 2008
·Updated
Directory traversal vulnerability in Dan Costin File Transfer before 1.2f allows remote attackers to read arbitrary files via a "..\" (dot dot backslash) in the filename.
Affected Software
4 affected components
File-transfer File Transfer=1.2d
File-transfer File Transfer=1.2c
File-transfer File Transfer=1.2e
File-transfer File Transfer=1.2b
Remediation
Patch Available
Event History
Mar 31, 2008
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-1564?
CVE-2008-1564 is rated as a medium severity vulnerability.
2
How do I fix CVE-2008-1564?
To fix CVE-2008-1564, upgrade to version 1.2f or later of the Dan Costin File Transfer software.
3
What type of vulnerability is CVE-2008-1564?
CVE-2008-1564 is a directory traversal vulnerability that allows unauthorized file access.
4
Which versions of File Transfer are affected by CVE-2008-1564?
CVE-2008-1564 affects versions 1.2b, 1.2c, 1.2d, and 1.2e of the Dan Costin File Transfer software.
5
Can CVE-2008-1564 be exploited remotely?
Yes, CVE-2008-1564 can be exploited remotely by attackers using specially crafted file requests.