Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2001-1043 | First vendor Publication | 2001-07-01 |
Vendor | Cve | Last vendor Modification | 2024-11-20 |
Security-Database Scoring CVSS v3
Cvss vector : CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N | |||
---|---|---|---|
Overall CVSS Score | 7.5 | ||
Base Score | 7.5 | Environmental Score | 7.5 |
impact SubScore | 3.6 | Temporal Score | 7.5 |
Exploitabality Sub Score | 3.9 | ||
Attack Vector | Network | Attack Complexity | Low |
Privileges Required | None | User Interaction | None |
Scope | Unchanged | Confidentiality Impact | High |
Integrity Impact | None | Availability Impact | None |
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:P/I:N/A:N) | |||
---|---|---|---|
Cvss Base Score | 5 | Attack Range | Network |
Cvss Impact Score | 2.9 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
ArGoSoft FTP Server 1.2.2.2 allows remote attackers to read arbitrary files and directories by uploading a .lnk (link) file that points to the target file. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1043 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-59 | Improper Link Resolution Before File Access ('Link Following') |
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 1 |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
11325 | ArGoSoft FTP Server .lnk Shortcut Upload Arbitrary File Manipulation ArGoSoft FTP Server contains a flaw that may allow a malicious user to upload .lnk shortcut files. The issue is due to an unknown error in the product. It is possible that the flaw may allow the malicious user to use the uploaded .lnk shortcut files to access arbitrary files and directories outside of the FTP base path resulting in a loss of confidentiality or integrity. |
1886 | ArGoSoft FTP Server .lnk Arbitrary File and Directory Access ArGoSoft FTP Server has a flaw that allows a remote attacker to access arbitrary files and directories outside of the FTP base path. The issue is due the server not properly checking permissions of .lnk files that are linked to arbitrary paths. By uploading a specially crafted .lnk file, an attacker can traverse out of the FTP base path to any directory. |
Sources (Detail)
Source | Url |
---|
Alert History
Date | Informations |
---|---|
2024-11-28 23:24:24 |
|
2024-11-28 12:04:44 |
|
2024-02-02 09:28:21 |
|
2021-05-04 12:01:29 |
|
2021-04-22 01:01:38 |
|
2020-05-23 00:14:45 |
|
2017-10-10 09:23:22 |
|
2016-06-28 14:57:15 |
|
2013-05-11 12:06:01 |
|