Vulnerabilities
Vulnerable Software
Coreftp:  >> Core Ftp  >> 2.0  Security Vulnerabilities
Core FTP / SFTP Server v2 Build 725 was discovered to allow unauthenticated attackers to cause a Denial of Service (DoS) via a crafted packet through the SSH service.
CVSS Score
5.5
EPSS Score
0.002
Published
2022-02-17
CoreFTP Server before 727 allows directory traversal (for file creation) by an authenticated attacker via ../ in an HTTP PUT request.
CVSS Score
6.5
EPSS Score
0.031
Published
2022-01-10
Buffer overflow vulnerability in Core FTP Server v2 Build 697, via a crafted username.
CVSS Score
7.5
EPSS Score
0.004
Published
2021-04-05
An issue was discovered in the SFTP Server component in Core FTP 2.0 Build 674. Using the MDTM FTP command, a remote attacker can use a directory traversal technique (..\..\) to browse outside the root directory to determine the existence of a file on the operating system, and its last modified date.
CVSS Score
5.3
EPSS Score
0.301
Published
2019-03-22
An issue was discovered in the SFTP Server component in Core FTP 2.0 Build 674. A directory traversal vulnerability exists using the SIZE command along with a \..\..\ substring, allowing an attacker to enumerate file existence based on the returned information.
CVSS Score
5.3
EPSS Score
0.225
Published
2019-03-22
The server in Core FTP 2.0 build 653 on 32-bit platforms allows remote attackers to cause a denial of service (daemon crash) via a crafted XRMD command.
CVSS Score
7.5
EPSS Score
0.198
Published
2019-01-02
Stack-based buffer overflow in Core FTP before 2.2 build 1785 allows remote FTP servers to execute arbitrary code via a crafted directory name in a CWD command reply.
CVSS Score
9.3
EPSS Score
0.021
Published
2014-04-04


Contact Us

Shodan ® - All rights reserved