Vulnerability Database

391,932

Total vulnerabilities in the database

CVE-2010-2425 — southrivertech / titan_ftp_server

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Directory traversal vulnerability in TitanFTPd in South River Technologies Titan FTP Server 8.10.1125, and probably earlier versions, allows remote authenticated users to read or delete arbitrary files via "..//" sequences in a COMB command.

  • Published: Jun 24, 2010
  • Updated: Sep 30, 2026
  • CVE: CVE-2010-2425
  • Severity: Medium
  • Exploit:
  • CISA KEV:

CVSS v2:

  • Severity: Medium
  • Score: 6.5
  • AV:N/AC:L/Au:S/C:P/I:P/A:P
Software Affected versions
southrivertech / titan_ftp_server <= 8.10.1125
southrivertech / titan_ftp_server = 1.0.17
southrivertech / titan_ftp_server = 1.0.18
southrivertech / titan_ftp_server = 1.0.19
southrivertech / titan_ftp_server = 1.0.20
southrivertech / titan_ftp_server = 1.0.21
southrivertech / titan_ftp_server = 1.0.22
southrivertech / titan_ftp_server = 1.0.23
southrivertech / titan_ftp_server = 1.0.24
southrivertech / titan_ftp_server = 1.0.25
southrivertech / titan_ftp_server = 1.0.26
southrivertech / titan_ftp_server = 1.0.27
southrivertech / titan_ftp_server = 1.0.28
southrivertech / titan_ftp_server = 1.0.29
southrivertech / titan_ftp_server = 1.0.30
southrivertech / titan_ftp_server = 1.0.31
southrivertech / titan_ftp_server = 1.1.33
southrivertech / titan_ftp_server = 1.11.34
southrivertech / titan_ftp_server = 2.0.44-beta
southrivertech / titan_ftp_server = 2.00.95
southrivertech / titan_ftp_server = 2.01.96
southrivertech / titan_ftp_server = 2.02.99
southrivertech / titan_ftp_server = 2.10.119
southrivertech / titan_ftp_server = 2.10.120
southrivertech / titan_ftp_server = 2.10.121
southrivertech / titan_ftp_server = 2.11.132
southrivertech / titan_ftp_server = 2.20.140
southrivertech / titan_ftp_server = 2.21.142
southrivertech / titan_ftp_server = 2.30.151
southrivertech / titan_ftp_server = 2.31.152
southrivertech / titan_ftp_server = 2.40.155
southrivertech / titan_ftp_server = 3.00.162
southrivertech / titan_ftp_server = 3.01.163
southrivertech / titan_ftp_server = 3.02.165
southrivertech / titan_ftp_server = 3.10.169
southrivertech / titan_ftp_server = 3.12.172
southrivertech / titan_ftp_server = 3.20.175
southrivertech / titan_ftp_server = 3.21.177
southrivertech / titan_ftp_server = 3.22.178
southrivertech / titan_ftp_server = 3.30.186
southrivertech / titan_ftp_server = 4.00.245
southrivertech / titan_ftp_server = 4.01.246
southrivertech / titan_ftp_server = 4.02.248
southrivertech / titan_ftp_server = 4.03.249
southrivertech / titan_ftp_server = 4.05.252
southrivertech / titan_ftp_server = 4.10.256
southrivertech / titan_ftp_server = 4.11.257
southrivertech / titan_ftp_server = 4.13.260
southrivertech / titan_ftp_server = 4.14.261
southrivertech / titan_ftp_server = 4.20.263
southrivertech / titan_ftp_server = 4.21.264
southrivertech / titan_ftp_server = 4.22.265
southrivertech / titan_ftp_server = 4.23.266
southrivertech / titan_ftp_server = 4.30.269
southrivertech / titan_ftp_server = 4.31.272
southrivertech / titan_ftp_server = 5.00.303
southrivertech / titan_ftp_server = 5.01.306
southrivertech / titan_ftp_server = 5.02.307
southrivertech / titan_ftp_server = 5.03.308
southrivertech / titan_ftp_server = 5.03.309
southrivertech / titan_ftp_server = 5.03.310
southrivertech / titan_ftp_server = 5.04.311
southrivertech / titan_ftp_server = 5.04.312
southrivertech / titan_ftp_server = 5.04.313
southrivertech / titan_ftp_server = 5.04.314
southrivertech / titan_ftp_server = 5.04.315
southrivertech / titan_ftp_server = 5.05.316
southrivertech / titan_ftp_server = 5.05.317
southrivertech / titan_ftp_server = 5.05.318
southrivertech / titan_ftp_server = 5.05.319
southrivertech / titan_ftp_server = 5.05.320
southrivertech / titan_ftp_server = 5.05.321
southrivertech / titan_ftp_server = 5.05.322
southrivertech / titan_ftp_server = 5.05.323
southrivertech / titan_ftp_server = 5.05.324
southrivertech / titan_ftp_server = 5.05.325
southrivertech / titan_ftp_server = 5.05.326
southrivertech / titan_ftp_server = 5.05.327
southrivertech / titan_ftp_server = 5.10.328
southrivertech / titan_ftp_server = 5.10.329
southrivertech / titan_ftp_server = 5.11.330
southrivertech / titan_ftp_server = 5.11.331
southrivertech / titan_ftp_server = 5.12.332
southrivertech / titan_ftp_server = 5.12.333
southrivertech / titan_ftp_server = 5.12.334
southrivertech / titan_ftp_server = 5.12.335
southrivertech / titan_ftp_server = 5.12.336
southrivertech / titan_ftp_server = 5.20.342
southrivertech / titan_ftp_server = 5.21.347
southrivertech / titan_ftp_server = 5.22.350
southrivertech / titan_ftp_server = 5.23.351
southrivertech / titan_ftp_server = 5.24.352
southrivertech / titan_ftp_server = 5.25.356
southrivertech / titan_ftp_server = 5.26.361
southrivertech / titan_ftp_server = 5.27.362
southrivertech / titan_ftp_server = 5.30.367
southrivertech / titan_ftp_server = 5.31.373
southrivertech / titan_ftp_server = 5.32.376
southrivertech / titan_ftp_server = 5.33.380
southrivertech / titan_ftp_server = 5.33.381
southrivertech / titan_ftp_server = 5.35.385
southrivertech / titan_ftp_server = 5.36.386
southrivertech / titan_ftp_server = 5.37.387
southrivertech / titan_ftp_server = 5.38.388
southrivertech / titan_ftp_server = 5.39.389
southrivertech / titan_ftp_server = 6.00.492
southrivertech / titan_ftp_server = 6.01.512
southrivertech / titan_ftp_server = 6.03.537
southrivertech / titan_ftp_server = 6.04.545
southrivertech / titan_ftp_server = 6.05.550
southrivertech / titan_ftp_server = 6.06.555
southrivertech / titan_ftp_server = 6.10.560
southrivertech / titan_ftp_server = 6.20.587
southrivertech / titan_ftp_server = 6.21.596
southrivertech / titan_ftp_server = 6.23.616
southrivertech / titan_ftp_server = 6.24.621
southrivertech / titan_ftp_server = 6.25.622
southrivertech / titan_ftp_server = 6.26.630
southrivertech / titan_ftp_server = 7.00
southrivertech / titan_ftp_server = 7.01
southrivertech / titan_ftp_server = 7.02
southrivertech / titan_ftp_server = 7.10
southrivertech / titan_ftp_server = 7.12
southrivertech / titan_ftp_server = 8.00
southrivertech / titan_ftp_server = 8.01
southrivertech / titan_ftp_server = 8.10

Frequently Asked Questions

A security vulnerability is a weakness in software, hardware, or configuration that can be exploited to compromise confidentiality, integrity, or availability. Many vulnerabilities are tracked as CVEs (Common Vulnerabilities and Exposures), which provide a standardized identifier so teams can coordinate patching, mitigation, and risk assessment across tools and vendors.

CVSS (Common Vulnerability Scoring System) estimates technical severity, but it doesn't automatically equal business risk. Prioritize using context like internet exposure, affected asset criticality, known exploitation (proof-of-concept or in-the-wild), and whether compensating controls exist. A "Medium" CVSS on an exposed, production system can be more urgent than a "Critical" on an isolated, non-production host.

A vulnerability is the underlying weakness. An exploit is the method or code used to take advantage of it. A zero-day is a vulnerability that is unknown to the vendor or has no publicly available fix when attackers begin using it. In practice, risk increases sharply when exploitation becomes reliable or widespread.

Recurring findings usually come from incomplete Asset Discovery, inconsistent patch management, inherited images, and configuration drift. In modern environments, you also need to watch the software supply chain: dependencies, containers, build pipelines, and third-party services can reintroduce the same weakness even after you patch a single host. Unknown or unmanaged assets (often called Shadow IT) are a common reason the same issues resurface.

Use a simple, repeatable triage model: focus first on externally exposed assets, high-value systems (identity, VPN, email, production), vulnerabilities with known exploits, and issues that enable remote code execution or privilege escalation. Then enforce patch SLAs and track progress using consistent metrics so remediation is steady, not reactive.

SynScan combines attack surface monitoring and continuous security auditing to keep your inventory current, flag high-impact vulnerabilities early, and help you turn raw findings into a practical remediation plan.