// For flags

CVE-2022-22836

CoreFTP Server build 725 - Directory Traversal (Authenticated)

Severity Score

6.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

2
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

CoreFTP Server before 727 allows directory traversal (for file creation) by an authenticated attacker via ../ in an HTTP PUT request.

CoreFTP Server versiones anteriores a 727 ,permite un salto de directorio (para la creación de archivos) por un atacante autenticado por medio de ../ en una petición HTTP PUT

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2022-01-08 CVE Reserved
  • 2022-01-08 CVE Published
  • 2022-01-10 First Exploit
  • 2024-08-03 CVE Updated
  • 2024-11-03 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Coreftp
Search vendor "Coreftp"
Core Ftp
Search vendor "Coreftp" for product "Core Ftp"
<= 1.2
Search vendor "Coreftp" for product "Core Ftp" and version " <= 1.2"
-
Affected
Coreftp
Search vendor "Coreftp"
Core Ftp
Search vendor "Coreftp" for product "Core Ftp"
2.0
Search vendor "Coreftp" for product "Core Ftp" and version "2.0"
build_639
Affected
Coreftp
Search vendor "Coreftp"
Core Ftp
Search vendor "Coreftp" for product "Core Ftp"
2.0
Search vendor "Coreftp" for product "Core Ftp" and version "2.0"
build_640
Affected
Coreftp
Search vendor "Coreftp"
Core Ftp
Search vendor "Coreftp" for product "Core Ftp"
2.0
Search vendor "Coreftp" for product "Core Ftp" and version "2.0"
build_641
Affected
Coreftp
Search vendor "Coreftp"
Core Ftp
Search vendor "Coreftp" for product "Core Ftp"
2.0
Search vendor "Coreftp" for product "Core Ftp" and version "2.0"
build_642
Affected
Coreftp
Search vendor "Coreftp"
Core Ftp
Search vendor "Coreftp" for product "Core Ftp"
2.0
Search vendor "Coreftp" for product "Core Ftp" and version "2.0"
build_645
Affected
Coreftp
Search vendor "Coreftp"
Core Ftp
Search vendor "Coreftp" for product "Core Ftp"
2.0
Search vendor "Coreftp" for product "Core Ftp" and version "2.0"
build_647
Affected
Coreftp
Search vendor "Coreftp"
Core Ftp
Search vendor "Coreftp" for product "Core Ftp"
2.0
Search vendor "Coreftp" for product "Core Ftp" and version "2.0"
build_649
Affected
Coreftp
Search vendor "Coreftp"
Core Ftp
Search vendor "Coreftp" for product "Core Ftp"
2.0
Search vendor "Coreftp" for product "Core Ftp" and version "2.0"
build_651
Affected
Coreftp
Search vendor "Coreftp"
Core Ftp
Search vendor "Coreftp" for product "Core Ftp"
2.0
Search vendor "Coreftp" for product "Core Ftp" and version "2.0"
build_653
Affected
Coreftp
Search vendor "Coreftp"
Core Ftp
Search vendor "Coreftp" for product "Core Ftp"
2.0
Search vendor "Coreftp" for product "Core Ftp" and version "2.0"
build_655
Affected
Coreftp
Search vendor "Coreftp"
Core Ftp
Search vendor "Coreftp" for product "Core Ftp"
2.0
Search vendor "Coreftp" for product "Core Ftp" and version "2.0"
build_656
Affected
Coreftp
Search vendor "Coreftp"
Core Ftp
Search vendor "Coreftp" for product "Core Ftp"
2.0
Search vendor "Coreftp" for product "Core Ftp" and version "2.0"
build_657
Affected
Coreftp
Search vendor "Coreftp"
Core Ftp
Search vendor "Coreftp" for product "Core Ftp"
2.0
Search vendor "Coreftp" for product "Core Ftp" and version "2.0"
build_658
Affected
Coreftp
Search vendor "Coreftp"
Core Ftp
Search vendor "Coreftp" for product "Core Ftp"
2.0
Search vendor "Coreftp" for product "Core Ftp" and version "2.0"
build_659
Affected
Coreftp
Search vendor "Coreftp"
Core Ftp
Search vendor "Coreftp" for product "Core Ftp"
2.0
Search vendor "Coreftp" for product "Core Ftp" and version "2.0"
build_665
Affected
Coreftp
Search vendor "Coreftp"
Core Ftp
Search vendor "Coreftp" for product "Core Ftp"
2.0
Search vendor "Coreftp" for product "Core Ftp" and version "2.0"
build_667
Affected
Coreftp
Search vendor "Coreftp"
Core Ftp
Search vendor "Coreftp" for product "Core Ftp"
2.0
Search vendor "Coreftp" for product "Core Ftp" and version "2.0"
build_668
Affected
Coreftp
Search vendor "Coreftp"
Core Ftp
Search vendor "Coreftp" for product "Core Ftp"
2.0
Search vendor "Coreftp" for product "Core Ftp" and version "2.0"
build_671
Affected
Coreftp
Search vendor "Coreftp"
Core Ftp
Search vendor "Coreftp" for product "Core Ftp"
2.0
Search vendor "Coreftp" for product "Core Ftp" and version "2.0"
build_673
Affected
Coreftp
Search vendor "Coreftp"
Core Ftp
Search vendor "Coreftp" for product "Core Ftp"
2.0
Search vendor "Coreftp" for product "Core Ftp" and version "2.0"
build_674
Affected
Coreftp
Search vendor "Coreftp"
Core Ftp
Search vendor "Coreftp" for product "Core Ftp"
2.0
Search vendor "Coreftp" for product "Core Ftp" and version "2.0"
build_676
Affected
Coreftp
Search vendor "Coreftp"
Core Ftp
Search vendor "Coreftp" for product "Core Ftp"
2.0
Search vendor "Coreftp" for product "Core Ftp" and version "2.0"
build_677
Affected
Coreftp
Search vendor "Coreftp"
Core Ftp
Search vendor "Coreftp" for product "Core Ftp"
2.0
Search vendor "Coreftp" for product "Core Ftp" and version "2.0"
build_679
Affected
Coreftp
Search vendor "Coreftp"
Core Ftp
Search vendor "Coreftp" for product "Core Ftp"
2.0
Search vendor "Coreftp" for product "Core Ftp" and version "2.0"
build_682
Affected
Coreftp
Search vendor "Coreftp"
Core Ftp
Search vendor "Coreftp" for product "Core Ftp"
2.0
Search vendor "Coreftp" for product "Core Ftp" and version "2.0"
build_687
Affected
Coreftp
Search vendor "Coreftp"
Core Ftp
Search vendor "Coreftp" for product "Core Ftp"
2.0
Search vendor "Coreftp" for product "Core Ftp" and version "2.0"
build_689
Affected
Coreftp
Search vendor "Coreftp"
Core Ftp
Search vendor "Coreftp" for product "Core Ftp"
2.0
Search vendor "Coreftp" for product "Core Ftp" and version "2.0"
build_691
Affected
Coreftp
Search vendor "Coreftp"
Core Ftp
Search vendor "Coreftp" for product "Core Ftp"
2.0
Search vendor "Coreftp" for product "Core Ftp" and version "2.0"
build_694
Affected
Coreftp
Search vendor "Coreftp"
Core Ftp
Search vendor "Coreftp" for product "Core Ftp"
2.0
Search vendor "Coreftp" for product "Core Ftp" and version "2.0"
build_695
Affected
Coreftp
Search vendor "Coreftp"
Core Ftp
Search vendor "Coreftp" for product "Core Ftp"
2.0
Search vendor "Coreftp" for product "Core Ftp" and version "2.0"
build_697
Affected
Coreftp
Search vendor "Coreftp"
Core Ftp
Search vendor "Coreftp" for product "Core Ftp"
2.0
Search vendor "Coreftp" for product "Core Ftp" and version "2.0"
build_699
Affected
Coreftp
Search vendor "Coreftp"
Core Ftp
Search vendor "Coreftp" for product "Core Ftp"
2.0
Search vendor "Coreftp" for product "Core Ftp" and version "2.0"
build_702
Affected
Coreftp
Search vendor "Coreftp"
Core Ftp
Search vendor "Coreftp" for product "Core Ftp"
2.0
Search vendor "Coreftp" for product "Core Ftp" and version "2.0"
build_704
Affected
Coreftp
Search vendor "Coreftp"
Core Ftp
Search vendor "Coreftp" for product "Core Ftp"
2.0
Search vendor "Coreftp" for product "Core Ftp" and version "2.0"
build_705
Affected
Coreftp
Search vendor "Coreftp"
Core Ftp
Search vendor "Coreftp" for product "Core Ftp"
2.0
Search vendor "Coreftp" for product "Core Ftp" and version "2.0"
build_711
Affected
Coreftp
Search vendor "Coreftp"
Core Ftp
Search vendor "Coreftp" for product "Core Ftp"
2.0
Search vendor "Coreftp" for product "Core Ftp" and version "2.0"
build_713
Affected
Coreftp
Search vendor "Coreftp"
Core Ftp
Search vendor "Coreftp" for product "Core Ftp"
2.0
Search vendor "Coreftp" for product "Core Ftp" and version "2.0"
build_715
Affected
Coreftp
Search vendor "Coreftp"
Core Ftp
Search vendor "Coreftp" for product "Core Ftp"
2.0
Search vendor "Coreftp" for product "Core Ftp" and version "2.0"
build_719
Affected
Coreftp
Search vendor "Coreftp"
Core Ftp
Search vendor "Coreftp" for product "Core Ftp"
2.0
Search vendor "Coreftp" for product "Core Ftp" and version "2.0"
build_725
Affected