CVE Vulnerabilities

CVE-2004-2487

Published: Dec 31, 2004 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Directory traversal vulnerability in Nexgen FTP Server before 2.2.3.23 allows remote authenticated users to read or list arbitrary files via (1) .., (2) .. (backslash dot dot), or (3) /../ sequences in (a) RETR (get), (b) NLST (ls), (c) LIST (ls), (d) RNFR, or (e) RNTO FTP commands.

Affected Software

NameVendorStart VersionEnd Version
Nexgen_ftp_serverNexgen1.0 (including)1.0 (including)
Nexgen_ftp_serverNexgen2.0 (including)2.0 (including)
Nexgen_ftp_serverNexgen2.1 (including)2.1 (including)
Nexgen_ftp_serverNexgen2.2 (including)2.2 (including)

References