VulnerabilityModified
CVE-2001-0263
Gene6 G6 FTP Server 2.0 (aka BPFTP Server 2.10) allows attackers to read file attributes outside of the web root via the (1) SIZE and (2) MDTM commands when the "show relative paths" option is not enabled.
HIGH 7.5EPSS 2.42%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.42%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Gene6 G6 FTP Server 2.0 (aka BPFTP Server 2.10) allows attackers to read file attributes outside of the web root via the (1) SIZE and (2) MDTM commands when the "show relative paths" option is not enabled.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 2.42% probability · 83th percentile
- CISA KEV
- Not listed
- Affected
- gene6/g6 ftp server
- Source
- cve@mitre.org
References
- http://www.atstake.com/research/advisories/2001/a040301-1.txt
- http://www.securityfocus.com/bid/2537
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6330
- http://www.atstake.com/research/advisories/2001/a040301-1.txt
- http://www.securityfocus.com/bid/2537
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6330
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.