Required CVE Record Information
Description
ArGoSoft FTP Server before 1.4.2.7 allows remote attackers to read arbitrary files by uploading a ZIP file containing a shortcut (.LNK) file, using SITE UNZIP to extract the .LNK file onto the server, then accessing the file, a different vulnerability than CVE-2005-0520.
References 5 Total
- securityfocus.com: 12487 vdb-entry
- osvdb.org: 13614 vdb-entry
- exchange.xforce.ibmcloud.com: argosoft-ink-file-upload(17939) vdb-entry
- http://www.argosoft.com/ftpserver/changelist.aspx
- secunia.com: 14172 third-party-advisory
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 5 Total
- securityfocus.com: 12487 vdb-entryx_transferred
- osvdb.org: 13614 vdb-entryx_transferred
- exchange.xforce.ibmcloud.com: argosoft-ink-file-upload(17939) vdb-entryx_transferred
- http://www.argosoft.com/ftpserver/changelist.aspx x_transferred
- secunia.com: 14172 third-party-advisoryx_transferred