VulnerabilityModified
CVE-2000-1101
Directory traversal vulnerability in Winsock FTPd (WFTPD) 3.00 and 2.41 with the "Restrict to home directory" option enabled allows local users to escape the home directory via a "/../" string, a variation of the ..
MEDIUM 5.0EPSS 1.86%
Does this matter?
Lower severity and a low EPSS score (1.86%). Track it; it rarely justifies an emergency change on its own.
Description
Directory traversal vulnerability in Winsock FTPd (WFTPD) 3.00 and 2.41 with the "Restrict to home directory" option enabled allows local users to escape the home directory via a "/../" string, a variation of the .. (dot dot) attack.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.86% probability · 78th percentile
- CISA KEV
- Not listed
- Affected
- texas imperial software/wftpd
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/bugtraq/2000-11/0386.htmlExploit, Patch, Vendor Advisory
- http://www.iss.net/security_center/static/5608.php
- http://www.securityfocus.com/bid/2005Exploit, Patch, Vendor Advisory
- http://archives.neohapsis.com/archives/bugtraq/2000-11/0386.htmlExploit, Patch, Vendor Advisory
- http://www.iss.net/security_center/static/5608.php
- http://www.securityfocus.com/bid/2005Exploit, Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.