CVE-2008-2795 Information
Feb 14, 2021
cve
Description
Directory traversal vulnerability in the FTP and SFTP clients in IDM Computer Solutions Inc UltraEdit 14.00b allows remote FTP servers to create or overwrite arbitrary files via a .. (dot dot) or a ..\ (dot dot backslash) in a response to a LIST command.
Reference
http://secunia.com/advisories/30749 http://vuln.sg/ultraedit1400b-en.html http://www.securityfocus.com/bid/29784 http://www.vupen.com/english/advisories/2008/1864/references https://exchange.xforce.ibmcloud.com/vulnerabilities/43149
Share on: