VulnerabilityModified
CVE-2010-2425
Directory traversal vulnerability in TitanFTPd in South River Technologies Titan FTP Server 8.10.1125, and probably earlier versions, allows remote authenticated users to read or delete arbitrary files via "..//" sequences in a COMB command.
MEDIUM 6.5EPSS 1.22%
Does this matter?
Lower severity and a low EPSS score (1.22%). Track it; it rarely justifies an emergency change on its own.
Description
Directory traversal vulnerability in TitanFTPd in South River Technologies Titan FTP Server 8.10.1125, and probably earlier versions, allows remote authenticated users to read or delete arbitrary files via "..//" sequences in a COMB command.
- CVSS 2.0
- 6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
- EPSS
- 1.22% probability · 67th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- southrivertech/titan ftp server
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/40237Vendor Advisory
- http://www.osvdb.org/65622
- http://www.securityfocus.com/archive/1/511873/100/0/threaded
- http://www.securityfocus.com/bid/40949
- http://secunia.com/advisories/40237Vendor Advisory
- http://www.osvdb.org/65622
- http://www.securityfocus.com/archive/1/511873/100/0/threaded
- http://www.securityfocus.com/bid/40949
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.