CVE-2014-1442: Path Traversal
Published May 2, 2014
·Updated
Directory traversal vulnerability in Core FTP Server 1.2 before build 515 allows remote authenticated users to determine the existence of arbitrary files via a /../ sequence in an XCRC command.
Affected Software
1 affected component
CoreFTP Core Ftp=1.2
Event History
May 2, 2014
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Data Sourced
via NVD·01:59 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-1442?
CVE-2014-1442 is rated as a medium severity vulnerability due to its potential to disclose file existence on the server.
2
How do I fix CVE-2014-1442?
To fix CVE-2014-1442, upgrade to Core FTP Server version 1.2 build 515 or later.
3
Who is affected by CVE-2014-1442?
CVE-2014-1442 affects remote authenticated users of Core FTP Server version 1.2 prior to build 515.
4
What is the impact of exploiting CVE-2014-1442?
Exploitation of CVE-2014-1442 allows remote authenticated users to ascertain the existence of arbitrary files on the server.
5
What is the nature of CVE-2014-1442 vulnerability?
CVE-2014-1442 is a directory traversal vulnerability that enables the use of '../' sequences in XCRC commands.