CVE-2009-4053
moderate-risk
Published 2009-11-23
Multiple directory traversal vulnerabilities in Home FTP Server 1.10.1.139 allow remote authenticated users to (1) create arbitrary directories via directory traversal sequences in an MKD command or (2) create files with any contents in arbitrary directories via directory traversal sequences in a file upload request. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Do I need to act?
~
4.3% chance of exploitation in next 30 days
EPSS score — moderate exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
!
1 public exploit available
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
6
CVSS 6.5/10
Medium
NETWORK
/ LOW complexity
Affected Products (1)
Affected Vendors
References (3)
Broken Link
http://secunia.com/advisories/37381
Third Party Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/54303
Broken Link
http://secunia.com/advisories/37381
43
/ 100
moderate-risk
Severity
24/34 · High
Exploitability
14/34 · Moderate
Exposure
5/34 · Minimal