CVE-2006-1383
Directory traversal vulnerability in Baby FTP Server (BabyFTP) 1.24 allows remote authenticated users to determine existence of files outside the intended document root via unspecified manipulations, which generate different error messages depending on…
Does this matter?
Lower severity and a low EPSS score (1.31%). Track it; it rarely justifies an emergency change on its own.
Description
Directory traversal vulnerability in Baby FTP Server (BabyFTP) 1.24 allows remote authenticated users to determine existence of files outside the intended document root via unspecified manipulations, which generate different error messages depending on whether a file exists or not.
- CVSS 2.0
- 4.0 MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
- EPSS
- 1.31% probability · 69th percentile
- CISA KEV
- Not listed
- Affected
- pablo software solutions/baby ftp server
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/19338Vendor Advisory
- http://www.osvdb.org/24057
- http://www.securityfocus.com/bid/17205
- http://www.vupen.com/english/advisories/2006/1069
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25413
- http://secunia.com/advisories/19338Vendor Advisory
- http://www.osvdb.org/24057
- http://www.securityfocus.com/bid/17205
- http://www.vupen.com/english/advisories/2006/1069
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25413
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.