First published: Fri May 02 2014(Updated: )
Directory traversal vulnerability in Core FTP Server 1.2 before build 515 allows remote authenticated users to determine the existence of arbitrary files via a /../ sequence in an XCRC command.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tsolucio Corebos | =1.2 | |
=1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-1442 is rated as a medium severity vulnerability due to its potential to disclose file existence on the server.
To fix CVE-2014-1442, upgrade to Core FTP Server version 1.2 build 515 or later.
CVE-2014-1442 affects remote authenticated users of Core FTP Server version 1.2 prior to build 515.
Exploitation of CVE-2014-1442 allows remote authenticated users to ascertain the existence of arbitrary files on the server.
CVE-2014-1442 is a directory traversal vulnerability that enables the use of '../' sequences in XCRC commands.