Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Directory traversal vulnerability in Core FTP client 2.1 Build 1565 allows remote FTP servers to create or overwrite arbitrary files via .. (dot dot) sequences in responses to LIST commands, a related issue to CVE-2002-1345. NOTE: this can be leveraged for code execution by writing to a Startup folder.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Core FTP 客户端 LIST命令响应目录遍历漏洞
Vulnerability Description
Core FTP是Core FTP社区的一套免费的FTP客户端软件。该软件支持文件的上传、下载、续传等。 Core FTP客户端没有正确地过滤FTP服务器响应LIST命令所返回的包含有目录遍历序列(斜线和反斜线)的文件名,如果用户受骗从恶意的FTP服务器下载了目录的话,就可能导致目录遍历攻击,以该用户的权限向系统中任意位置写入文件。
CVSS Information
N/A
Vulnerability Type
N/A