CVE-2019-9649: Path Traversal
An issue was discovered in the SFTP Server component in Core FTP 2.0 Build 674. Using the MDTM FTP command, a remote attacker can use a directory traversal technique (..\..\) to browse outside the root directory to determine the existence of a file on the operating system, and its last modified date.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue in Core FTP 2.0 Build 674?
The vulnerability ID is CVE-2019-9649.
What is the severity rating of CVE-2019-9649?
The severity rating of CVE-2019-9649 is medium with a CVSS score of 5.3.
What is the affected software version?
The affected software version is Core FTP 2.0 Build 674.
What is the nature of the vulnerability in Core FTP 2.0 Build 674?
The vulnerability allows a remote attacker to use a directory traversal technique to browse outside the root directory and determine the existence of a file on the operating system.
Are there any references available for more information?
Yes, you can find more information about this vulnerability at the following references: [Packet Storm](http://packetstormsecurity.com/files/154205/CoreFTP-Server-MDTM-Directory-Traversal.html), [SecLists](http://seclists.org/fulldisclosure/2019/Aug/22), [Core FTP Forums](http://www.coreftp.com/forums/viewtopic.php?f=15&t=4022509).