6.5

CVE-2022-22836

Exploit
CoreFTP Server before 727 allows directory traversal (for file creation) by an authenticated attacker via ../ in an HTTP PUT request.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
CoreftpCore Ftp Version <= 1.2
CoreftpCore Ftp Version2.0 Updatebuild_639
CoreftpCore Ftp Version2.0 Updatebuild_640
CoreftpCore Ftp Version2.0 Updatebuild_641
CoreftpCore Ftp Version2.0 Updatebuild_642
CoreftpCore Ftp Version2.0 Updatebuild_645
CoreftpCore Ftp Version2.0 Updatebuild_647
CoreftpCore Ftp Version2.0 Updatebuild_649
CoreftpCore Ftp Version2.0 Updatebuild_651
CoreftpCore Ftp Version2.0 Updatebuild_653
CoreftpCore Ftp Version2.0 Updatebuild_655
CoreftpCore Ftp Version2.0 Updatebuild_656
CoreftpCore Ftp Version2.0 Updatebuild_657
CoreftpCore Ftp Version2.0 Updatebuild_658
CoreftpCore Ftp Version2.0 Updatebuild_659
CoreftpCore Ftp Version2.0 Updatebuild_665
CoreftpCore Ftp Version2.0 Updatebuild_667
CoreftpCore Ftp Version2.0 Updatebuild_668
CoreftpCore Ftp Version2.0 Updatebuild_671
CoreftpCore Ftp Version2.0 Updatebuild_673
CoreftpCore Ftp Version2.0 Updatebuild_674
CoreftpCore Ftp Version2.0 Updatebuild_676
CoreftpCore Ftp Version2.0 Updatebuild_677
CoreftpCore Ftp Version2.0 Updatebuild_679
CoreftpCore Ftp Version2.0 Updatebuild_682
CoreftpCore Ftp Version2.0 Updatebuild_687
CoreftpCore Ftp Version2.0 Updatebuild_689
CoreftpCore Ftp Version2.0 Updatebuild_691
CoreftpCore Ftp Version2.0 Updatebuild_694
CoreftpCore Ftp Version2.0 Updatebuild_695
CoreftpCore Ftp Version2.0 Updatebuild_697
CoreftpCore Ftp Version2.0 Updatebuild_699
CoreftpCore Ftp Version2.0 Updatebuild_702
CoreftpCore Ftp Version2.0 Updatebuild_704
CoreftpCore Ftp Version2.0 Updatebuild_705
CoreftpCore Ftp Version2.0 Updatebuild_711
CoreftpCore Ftp Version2.0 Updatebuild_713
CoreftpCore Ftp Version2.0 Updatebuild_715
CoreftpCore Ftp Version2.0 Updatebuild_719
CoreftpCore Ftp Version2.0 Updatebuild_725
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.13% 0.864
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
nvd@nist.gov 4 8 2.9
AV:N/AC:L/Au:S/C:N/I:P/A:N
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.