Directory traversal vulnerability in the FireFTP add-on before 0.98.20080518 for Firefox allows remote FTP servers to create or overwrite arbitrary files via ..\ (dot dot backslash) sequences in responses to (1) MLSD and (2) LIST commands, a related issue to CVE-2002-1345.  NOTE: this can be leveraged for code execution by writing to a Startup folder.
                
            References
                    Configurations
                    Configuration 1 (hide)
            
            
  | 
    
History
                    No history.
Information
                Published : 2008-05-22 13:09
Updated : 2025-04-09 00:30
NVD link : CVE-2008-2399
Mitre link : CVE-2008-2399
CVE.ORG link : CVE-2008-2399
JSON object : View
Products Affected
                mozilla
- firefox
 
fireftp
- fireftp
 
CWE
                
                    
                        
                        CWE-22
                        
            Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
