CVE-2019-9648: Path Traversal
An issue was discovered in the SFTP Server component in Core FTP 2.0 Build 674. A directory traversal vulnerability exists using the SIZE command along with a \..\..\ substring, allowing an attacker to enumerate file existence based on the returned information.
Other sources
An issue was discovered in the SFTP Server component in Core FTP 2.0 Build 674. A directory traversal vulnerability exists using the SIZE command along with a \..\..\ substring, allowing an attacker to enumerate file existence based on the returned information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-9648?
The severity of CVE-2019-9648 is classified as medium due to the potential for enumeration of file existence.
How do I fix CVE-2019-9648?
To fix CVE-2019-9648, update to a later version of Core FTP that patches the directory traversal vulnerability.
What software is affected by CVE-2019-9648?
CVE-2019-9648 affects Core FTP version 2.0 and earlier.
Can CVE-2019-9648 be exploited remotely?
Yes, CVE-2019-9648 can be exploited remotely by attackers sending specially crafted SIZE commands.
What impact does CVE-2019-9648 have on security?
CVE-2019-9648 allows attackers to enumerate file existence, which can lead to further attacks if sensitive files are discovered.