← All CVEs

CVE-2010-2426

medium · 4

Directory traversal vulnerability in TitanFTPd in South River Technologies Titan FTP Server 8.10.1125, and probably earlier versions, allows remote authenticated users to read arbitrary files, determine file size, via "..//" sequences in the xcrc command.

4
CVSS
12.3%
EPSS (exploit prob.)
96th
EPSS percentile
2010-06-24
Published

AV:N/AC:L/Au:S/C:P/I:N/A:N

Weaknesses

CWE-22

Affected products

VendorProductAffected versions
southrivertechtitan_ftp_server<= 8.10.1125
southrivertechtitan_ftp_server1.0.17
southrivertechtitan_ftp_server1.0.18
southrivertechtitan_ftp_server1.0.19
southrivertechtitan_ftp_server1.0.20
southrivertechtitan_ftp_server1.0.21
southrivertechtitan_ftp_server1.0.22
southrivertechtitan_ftp_server1.0.23
southrivertechtitan_ftp_server1.0.24
southrivertechtitan_ftp_server1.0.25
southrivertechtitan_ftp_server1.0.26
southrivertechtitan_ftp_server1.0.27
southrivertechtitan_ftp_server1.0.28
southrivertechtitan_ftp_server1.0.29
southrivertechtitan_ftp_server1.0.30
southrivertechtitan_ftp_server1.0.31
southrivertechtitan_ftp_server1.1.33
southrivertechtitan_ftp_server1.11.34
southrivertechtitan_ftp_server2.0.44
southrivertechtitan_ftp_server2.00.95
southrivertechtitan_ftp_server2.01.96
southrivertechtitan_ftp_server2.02.99
southrivertechtitan_ftp_server2.10.119
southrivertechtitan_ftp_server2.10.120
southrivertechtitan_ftp_server2.10.121
southrivertechtitan_ftp_server2.11.132
southrivertechtitan_ftp_server2.20.140
southrivertechtitan_ftp_server2.21.142
southrivertechtitan_ftp_server2.30.151
southrivertechtitan_ftp_server2.31.152
southrivertechtitan_ftp_server2.40.155
southrivertechtitan_ftp_server3.00.162
southrivertechtitan_ftp_server3.01.163
southrivertechtitan_ftp_server3.02.165
southrivertechtitan_ftp_server3.10.169
southrivertechtitan_ftp_server3.12.172
southrivertechtitan_ftp_server3.20.175
southrivertechtitan_ftp_server3.21.177
southrivertechtitan_ftp_server3.22.178
southrivertechtitan_ftp_server3.30.186

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2010-2426