Directory traversal vulnerability in the FTP and SFTP clients in IDM Computer Solutions Inc UltraEdit 14.00b allows remote FTP servers to create or overwrite arbitrary files via a .. (dot dot) or a ..\ (dot dot backslash) in a response to a LIST command.
References
Configurations
Information
Published : 2008-06-20 04:48
Updated : 2017-08-07 18:31
NVD link : CVE-2008-2795
Mitre link : CVE-2008-2795
JSON object : View
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Products Affected
idm_computer_solutions_inc
- ultraedit