6.5

CVE-2022-22836

Exploit
CoreFTP Server before 727 allows directory traversal (for file creation) by an authenticated attacker via ../ in an HTTP PUT request.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Coreftp ≫ Core Ftp Version <= 1.2
Coreftp ≫ Core Ftp Version 2.0 Update build_639
Coreftp ≫ Core Ftp Version 2.0 Update build_640
Coreftp ≫ Core Ftp Version 2.0 Update build_641
Coreftp ≫ Core Ftp Version 2.0 Update build_642
Coreftp ≫ Core Ftp Version 2.0 Update build_645
Coreftp ≫ Core Ftp Version 2.0 Update build_647
Coreftp ≫ Core Ftp Version 2.0 Update build_649
Coreftp ≫ Core Ftp Version 2.0 Update build_651
Coreftp ≫ Core Ftp Version 2.0 Update build_653
Coreftp ≫ Core Ftp Version 2.0 Update build_655
Coreftp ≫ Core Ftp Version 2.0 Update build_656
Coreftp ≫ Core Ftp Version 2.0 Update build_657
Coreftp ≫ Core Ftp Version 2.0 Update build_658
Coreftp ≫ Core Ftp Version 2.0 Update build_659
Coreftp ≫ Core Ftp Version 2.0 Update build_665
Coreftp ≫ Core Ftp Version 2.0 Update build_667
Coreftp ≫ Core Ftp Version 2.0 Update build_668
Coreftp ≫ Core Ftp Version 2.0 Update build_671
Coreftp ≫ Core Ftp Version 2.0 Update build_673
Coreftp ≫ Core Ftp Version 2.0 Update build_674
Coreftp ≫ Core Ftp Version 2.0 Update build_676
Coreftp ≫ Core Ftp Version 2.0 Update build_677
Coreftp ≫ Core Ftp Version 2.0 Update build_679
Coreftp ≫ Core Ftp Version 2.0 Update build_682
Coreftp ≫ Core Ftp Version 2.0 Update build_687
Coreftp ≫ Core Ftp Version 2.0 Update build_689
Coreftp ≫ Core Ftp Version 2.0 Update build_691
Coreftp ≫ Core Ftp Version 2.0 Update build_694
Coreftp ≫ Core Ftp Version 2.0 Update build_695
Coreftp ≫ Core Ftp Version 2.0 Update build_697
Coreftp ≫ Core Ftp Version 2.0 Update build_699
Coreftp ≫ Core Ftp Version 2.0 Update build_702
Coreftp ≫ Core Ftp Version 2.0 Update build_704
Coreftp ≫ Core Ftp Version 2.0 Update build_705
Coreftp ≫ Core Ftp Version 2.0 Update build_711
Coreftp ≫ Core Ftp Version 2.0 Update build_713
Coreftp ≫ Core Ftp Version 2.0 Update build_715
Coreftp ≫ Core Ftp Version 2.0 Update build_719
Coreftp ≫ Core Ftp Version 2.0 Update build_725
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.37% 0.916
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
NIST 4 8 2.9
AV:N/AC:L/Au:S/C:N/I:P/A:N
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

http://www.coreftp.com/forums/viewtopic.php?f=15&t=4022509
Vendor Advisory
Release Notes
https://yoursecuritybores.me/coreftp-vulnerabilities/
Third Party Advisory
Exploit