VulnerabilityModified
CVE-2008-1221
Absolute path traversal vulnerability in the FTP server in MicroWorld eScan Corporate Edition 9.0.742.98 and eScan Management Console (aka eScan Server) 9.0.742.1 allows remote attackers to read arbitrary files via an absolute pathname in the RETR (get)…
MEDIUM 5.0EPSS 3.12%
Does this matter?
Lower severity and a low EPSS score (3.12%). Track it; it rarely justifies an emergency change on its own.
Description
Absolute path traversal vulnerability in the FTP server in MicroWorld eScan Corporate Edition 9.0.742.98 and eScan Management Console (aka eScan Server) 9.0.742.1 allows remote attackers to read arbitrary files via an absolute pathname in the RETR (get) command.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 3.12% probability · 87th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- microworld technologies/escan · microworld technologies/escan management console · microworld technologies/escan server
- Source
- cve@mitre.org
References
- http://aluigi.altervista.org/adv/escaz-adv.txtExploit
- http://secunia.com/advisories/29246Exploit, Vendor Advisory
- http://securityreason.com/securityalert/3723
- http://www.securityfocus.com/archive/1/489228/100/0/threaded
- http://www.securityfocus.com/bid/28127Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41033
- http://aluigi.altervista.org/adv/escaz-adv.txtExploit
- http://secunia.com/advisories/29246Exploit, Vendor Advisory
- http://securityreason.com/securityalert/3723
- http://www.securityfocus.com/archive/1/489228/100/0/threaded
- http://www.securityfocus.com/bid/28127Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41033
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.