VulnerabilityModified
CVE-2003-1299
Directory traversal vulnerability in Baby FTP Server 1.2, and possibly other versions before May 31, 2003 allows remote authenticated users to list arbitrary directories and possibly read files via "..." (triple dot) manipulations to the CWD command.
MEDIUM 4.0EPSS 1.43%
Does this matter?
Lower severity and a low EPSS score (1.43%). Track it; it rarely justifies an emergency change on its own.
Description
Directory traversal vulnerability in Baby FTP Server 1.2, and possibly other versions before May 31, 2003 allows remote authenticated users to list arbitrary directories and possibly read files via "..." (triple dot) manipulations to the CWD command.
- CVSS 2.0
- 4.0 MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
- EPSS
- 1.43% probability · 71th percentile
- CISA KEV
- Not listed
- Affected
- pablo software solutions/baby ftp server
- Source
- cve@mitre.org
References
- http://packetstormsecurity.org/0305-exploits/baby.txtExploit
- http://www.osvdb.org/24538
- http://www.pablosoftwaresolutions.com/html/baby_ftp_server.htmlPatch
- http://www.securityfocus.com/bid/7749
- http://packetstormsecurity.org/0305-exploits/baby.txtExploit
- http://www.osvdb.org/24538
- http://www.pablosoftwaresolutions.com/html/baby_ftp_server.htmlPatch
- http://www.securityfocus.com/bid/7749
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.