jarle aase war ftpd 1.67 b04 - Directory Traversal
Author: se00020
type: remote
platform: windows
port:
date_added: 2001-03-06
date_updated: 2012-08-20
verified: 1
codes: CVE-2001-0295;OSVDB-874
tags:
aliases:
screenshot_url:
application_url:
source: https://www.securityfocus.com/bid/2444/info
A remote user could gain read access to directories outside of the ftp root in a Jarle Aase War FTPD Server. Once a user is logged into the server, a specially crafted 'dir' command will disclose an arbitrary directory. This vulnerability could allow an attacker to gain read access to various files residing on the target machine.
dir *./../..