Directory traversal vulnerability in FTP Serv-U before 2.5i allows remote attackers to escape the FTP root and read arbitrary files by appending a string such as "/..%20." to a CD command, a variant of a .. (dot dot) attack.
Software | From | Fixed in |
---|---|---|
solarwinds / serv-u_file_server | 3.0.0.16 | 3.0.0.16.x |