Directory traversal vulnerability in the FTP and SFTP clients in IDM Computer Solutions Inc UltraEdit 14.00b allows remote FTP servers to create or overwrite arbitrary files via a .. (dot dot) or a ..\ (dot dot backslash) in a response to a LIST command.
References
Configurations
History
No history.
Information
Published : 2008-06-20 11:48
Updated : 2025-04-09 00:30
NVD link : CVE-2008-2795
Mitre link : CVE-2008-2795
CVE.ORG link : CVE-2008-2795
JSON object : View
Products Affected
idm_computer_solutions_inc
- ultraedit
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')