CVE-2001-1386 Information

Description

WFTPD 3.00 allows remote attackers to read arbitrary files by uploading a (link) file that ends in a .lnk.\ extension which bypasses WFTPD’s check for a .lnk\ extension.

Reference

http://www.securityfocus.com/archive/1/194442 http://www.securityfocus.com/bid/2957 https://exchange.xforce.ibmcloud.com/vulnerabilities/6760

Share on: