Vulnerability CVE-2022-22836


Published: 2022-01-10

Description:
CoreFTP Server before 727 allows directory traversal (for file creation) by an authenticated attacker via ../ in an HTTP PUT request.

See advisories in our WLB2 database:
Topic
Author
Date
Med.
CoreFTP Server Build 725 Directory Traversal
LiamInfosec
10.01.2022

Type:

CWE-22

(Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'))

 References:
https://yoursecuritybores.me/coreftp-vulnerabilities/
http://www.coreftp.com/forums/viewtopic.php?f=15&t=4022509

Copyright 2024, cxsecurity.com

 

Back to Top