CVE-2010-2426
medium · 4Directory traversal vulnerability in TitanFTPd in South River Technologies Titan FTP Server 8.10.1125, and probably earlier versions, allows remote authenticated users to read arbitrary files, determine file size, via "..//" sequences in the xcrc command.
4
CVSS
12.3%
EPSS (exploit prob.)
96th
EPSS percentile
2010-06-24
Published
AV:N/AC:L/Au:S/C:P/I:N/A:N
Weaknesses
CWE-22
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| southrivertech | titan_ftp_server | <= 8.10.1125 |
| southrivertech | titan_ftp_server | 1.0.17 |
| southrivertech | titan_ftp_server | 1.0.18 |
| southrivertech | titan_ftp_server | 1.0.19 |
| southrivertech | titan_ftp_server | 1.0.20 |
| southrivertech | titan_ftp_server | 1.0.21 |
| southrivertech | titan_ftp_server | 1.0.22 |
| southrivertech | titan_ftp_server | 1.0.23 |
| southrivertech | titan_ftp_server | 1.0.24 |
| southrivertech | titan_ftp_server | 1.0.25 |
| southrivertech | titan_ftp_server | 1.0.26 |
| southrivertech | titan_ftp_server | 1.0.27 |
| southrivertech | titan_ftp_server | 1.0.28 |
| southrivertech | titan_ftp_server | 1.0.29 |
| southrivertech | titan_ftp_server | 1.0.30 |
| southrivertech | titan_ftp_server | 1.0.31 |
| southrivertech | titan_ftp_server | 1.1.33 |
| southrivertech | titan_ftp_server | 1.11.34 |
| southrivertech | titan_ftp_server | 2.0.44 |
| southrivertech | titan_ftp_server | 2.00.95 |
| southrivertech | titan_ftp_server | 2.01.96 |
| southrivertech | titan_ftp_server | 2.02.99 |
| southrivertech | titan_ftp_server | 2.10.119 |
| southrivertech | titan_ftp_server | 2.10.120 |
| southrivertech | titan_ftp_server | 2.10.121 |
| southrivertech | titan_ftp_server | 2.11.132 |
| southrivertech | titan_ftp_server | 2.20.140 |
| southrivertech | titan_ftp_server | 2.21.142 |
| southrivertech | titan_ftp_server | 2.30.151 |
| southrivertech | titan_ftp_server | 2.31.152 |
| southrivertech | titan_ftp_server | 2.40.155 |
| southrivertech | titan_ftp_server | 3.00.162 |
| southrivertech | titan_ftp_server | 3.01.163 |
| southrivertech | titan_ftp_server | 3.02.165 |
| southrivertech | titan_ftp_server | 3.10.169 |
| southrivertech | titan_ftp_server | 3.12.172 |
| southrivertech | titan_ftp_server | 3.20.175 |
| southrivertech | titan_ftp_server | 3.21.177 |
| southrivertech | titan_ftp_server | 3.22.178 |
| southrivertech | titan_ftp_server | 3.30.186 |
Check a specific version with /api/v1/cve/match.
References
- http://osvdb.org/65533
- http://secunia.com/advisories/40237
- http://www.securityfocus.com/archive/1/511839/100/0/threaded
- http://www.securityfocus.com/bid/40949
- https://exchange.xforce.ibmcloud.com/vulnerabilities/59492
- http://osvdb.org/65533
- http://secunia.com/advisories/40237
- http://www.securityfocus.com/archive/1/511839/100/0/threaded
- http://www.securityfocus.com/bid/40949
- https://exchange.xforce.ibmcloud.com/vulnerabilities/59492
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2010-2426