CVE Database
/

CVE-2007-4843

Back to search

CVE-2007-4843

Published: Sep 12, 2007

Modified: Aug 7, 2024

PUBLISHED

Description

Directory traversal vulnerability in X-Diesel Unreal Commander 0.92 build 565 and 573 allows remote FTP servers to create or overwrite arbitrary files via a .. (dot dot) in a filename. NOTE: this can be leveraged for code execution by writing to a Startup folder.

VendorProductVersions

n/a

n/a

affected
n/a

References

3125
third-party-advisory
x_refsource_SREASON
39615
vdb-entry
x_refsource_OSVDB
25583
vdb-entry
x_refsource_BID
26739
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now