CVE-2008-4501
Directory traversal vulnerability in the FTP server in Serv-U 7.0.0.1 through 7.3, including 7.2.0.1, allows remote authenticated users to overwrite or create arbitrary files via a ..\ (dot dot backslash) in the RNTO command.
- Affected products
- Serv-U
- Solarwinds Serv-u File Server
- = 7.0.0.1, 7.0.0.2, 7.0.0.3, 7.0.0.4, 7.1.0.0, 7.1.0.1, 7.1.0.2, 7.2.0.0, 7.2.0.1, 7.3.0.0, 7.3.0.1, 7.3.0.2
- Fix
- Available
- CVSS 2.0
- 9.0 HIGH
- EPSS
- 10.7% (95th percentile)
- Weakness
- CWE-22
- NVD status
- Modified
- Published
- 2008-10-08
CVE-2008-4501 at NVD
1 known exploit for CVE-2008-4501
Proof-of-concept code and exploit modules indexed by Sploitus