Multiple directory traversal vulnerabilities in sitenfo.sh, sitezipchk.sh, and siteziplist.sh in Glftpd 1.26 to 2.00 allow remote authenticated users to (1) determine the existence of arbitrary files, (2) list files in restricted directories, or (3) read arbitrary files from within ZIP or gzip files, via .. (dot dot) sequences and globbing ("*") characters in a SITE NFO command.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published: 2005-02-19T05:00:00
Updated: 2024-08-07T21:13:54.238Z
Reserved: 2005-02-19T00:00:00
Link: CVE-2005-0483

No data.

Status : Modified
Published: 2005-03-30T05:00:00.000
Modified: 2024-11-20T23:55:14.300
Link: CVE-2005-0483

No data.