First published: Mon Jun 23 2008(Updated: )
Directory traversal vulnerability in the FTP client in Glub Tech Secure FTP before 2.5.16 on Windows allows remote FTP servers to create or overwrite arbitrary files via a ..\ (dot dot backslash) in a response to a LIST command, a related issue to CVE-2002-1345.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows NT | ||
Glub Secure FTP | <=2.5.15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-2821 is considered a moderate severity vulnerability due to its potential to be exploited for unauthorized file access.
To mitigate CVE-2008-2821, upgrade to Glub Tech Secure FTP version 2.5.16 or later.
CVE-2008-2821 affects Glub Tech Secure FTP versions before 2.5.16 running on Windows.
CVE-2008-2821 allows for a directory traversal attack that can lead to file creation or overwriting.
CVE-2008-2821 is specifically related to Glub Tech Secure FTP and does not mention other software vulnerabilities.