Page 2 of 7 results (0.004 seconds)

CVSS: 6.5EPSS: 0%CPEs: 126EXPL: 0

Directory traversal vulnerability in TitanFTPd in South River Technologies Titan FTP Server 8.10.1125, and probably earlier versions, allows remote authenticated users to read or delete arbitrary files via "..//" sequences in a COMB command. Vulnerabilidad de salto de directorio en TitanFTPd en South River Technologies Titan FTP Server v8.10.1125, y probablemente versiones anteriores, permite a usuarios autentificados remotamente leer ficheroso borrar ficheros de su elección a través de la secuencia "..//" en el comando COMB. • http://secunia.com/advisories/40237 http://www.osvdb.org/65622 http://www.securityfocus.com/archive/1/511873/100/0/threaded http://www.securityfocus.com/bid/40949 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVSS: 10.0EPSS: 29%CPEs: 1EXPL: 2

Heap-based buffer overflow in Titan FTP Server 6.05 build 550 allows remote attackers to execute arbitrary code via a long DELE command. Desbordamiento de búfer basado en montículo en el servidor FTP Titan v6.05 build 550 permite a atacantes remotos ejecutar código de su elección a través de un comando "DELE" largo. • https://www.exploit-db.com/exploits/31105 http://packetstormsecurity.org/0802-exploits/titan-heap-py.txt http://www.securityfocus.com/bid/27611 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •