Directory traversal vulnerability in ftpd in QPC QVT/Net 4.0 and AVT/Term 5.0 allows a remote attacker to traverse directories on the web server via a "dot dot" attack in a LIST (ls) command.
| Software | From | Fixed in |
|---|---|---|
| qpc_software / qvt_net | 4.0 | 4.0.x |
| qpc_software / qvt_net | 5.0 | 5.0.x |
| qpc_software / avt_term | 5.0 | 5.0.x |