CVE-2008-2821 – Glub Tech Secure FTP 2.5.15 - 'LIST' Directory Traversal
https://notcve.org/view.php?id=CVE-2008-2821
Directory traversal vulnerability in the FTP client in Glub Tech Secure FTP before 2.5.16 on Windows allows remote FTP servers to create or overwrite arbitrary files via a ..\ (dot dot backslash) in a response to a LIST command, a related issue to CVE-2002-1345. Vulnerabilidad de salto de directorio en el Cliente FTP para Windows de Glub Tech Secure FTP anterior a 2..5.16, permite a los servidores FTP remotos crear o sobreescribir ficheros de su elección a través de una secuencia "..\" en respuesta a un comando LIST. Relacionada con el CVE-2002-1345. • https://www.exploit-db.com/exploits/31920 http://secunia.com/advisories/30725 http://vuln.sg/glubsecureftp2515-en.html http://www.securityfocus.com/bid/29741 http://www.vupen.com/english/advisories/2008/1852/references https://exchange.xforce.ibmcloud.com/vulnerabilities/43093 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •