ID

VAR-200102-0026


CVE

CVE-2001-0054


TITLE

SolarWinds Serv-U File Server Path traversal vulnerability

Trust: 0.6

sources: CNNVD: CNNVD-200102-085

DESCRIPTION

Directory traversal vulnerability in FTP Serv-U before 2.5i allows remote attackers to escape the FTP root and read arbitrary files by appending a string such as "/..%20." to a CD command, a variant of a .. (dot dot) attack. FTP Serv-U is an internet FTP server from CatSoft. Authenticated users can gain access to the ftproot of the drive where Serv-U FTP has been installed. Users that have read, write, execute and list access in the home directory will have the same permissions to any file which resides on the same partition as the ftproot, once a user is in the home directory they can successfully transfer any files using specially crafted GET requests. All hidden files will be revealed even if the 'Hide hidden files' feature is on. Successful exploitation of this vulnerability could enable a remote user to gain access to systems files, password files, etc. This could lead to a complete compromise of the host

Trust: 1.17

sources: NVD: CVE-2001-0054 // BID: 2052

AFFECTED PRODUCTS

vendor:solarwindsmodel:serv-u file serverscope:eqversion:3.0.0.16

Trust: 1.0

vendor:serv umodel:serv-uscope:eqversion:3.0.0.16

Trust: 0.6

vendor:catmodel:soft serv-uscope:eqversion:2.5

Trust: 0.3

vendor:catmodel:soft serv-uscope:eqversion:2.4

Trust: 0.3

vendor:catmodel:soft serv-u iscope:neversion:2.5

Trust: 0.3

sources: BID: 2052 // CNNVD: CNNVD-200102-085 // NVD: CVE-2001-0054

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2001-0054
value: MEDIUM

Trust: 1.0

CNNVD: CNNVD-200102-085
value: MEDIUM

Trust: 0.6

nvd@nist.gov: CVE-2001-0054
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

sources: CNNVD: CNNVD-200102-085 // NVD: CVE-2001-0054

PROBLEMTYPE DATA

problemtype:CWE-22

Trust: 1.0

sources: NVD: CVE-2001-0054

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200102-085

TYPE

path traversal

Trust: 0.6

sources: CNNVD: CNNVD-200102-085

PATCH

title:SolarWinds Serv-U File Server Repair measures for path traversal vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=125162

Trust: 0.6

sources: CNNVD: CNNVD-200102-085

EXTERNAL IDS

db:BIDid:2052

Trust: 1.9

db:OSVDBid:464

Trust: 1.6

db:NVDid:CVE-2001-0054

Trust: 1.6

db:NSFOCUSid:1094

Trust: 0.6

db:CNNVDid:CNNVD-200102-085

Trust: 0.6

sources: BID: 2052 // CNNVD: CNNVD-200102-085 // NVD: CVE-2001-0054

REFERENCES

url:http://www.securityfocus.com/bid/2052

Trust: 1.6

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/5639

Trust: 1.6

url:http://archives.neohapsis.com/archives/bugtraq/2000-12/0043.html

Trust: 1.6

url:http://marc.info/?l=bugtraq&m=97604119024280&w=2

Trust: 1.6

url:http://www.osvdb.org/464

Trust: 1.6

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2001-0054

Trust: 0.6

url:http://www.nsfocus.net/vulndb/1094

Trust: 0.6

url:http://ftpservu.deerfield.com/

Trust: 0.3

sources: BID: 2052 // CNNVD: CNNVD-200102-085 // NVD: CVE-2001-0054

CREDITS

Zoa_Chien※ zoachien@securax.org

Trust: 0.6

sources: CNNVD: CNNVD-200102-085

SOURCES

db:BIDid:2052
db:CNNVDid:CNNVD-200102-085
db:NVDid:CVE-2001-0054

LAST UPDATE DATE

2024-08-14T15:31:20.828000+00:00


SOURCES UPDATE DATE

db:BIDid:2052date:2000-12-05T00:00:00
db:CNNVDid:CNNVD-200102-085date:2020-07-29T00:00:00
db:NVDid:CVE-2001-0054date:2020-07-28T14:34:00.110

SOURCES RELEASE DATE

db:BIDid:2052date:2000-12-05T00:00:00
db:CNNVDid:CNNVD-200102-085date:2000-12-06T00:00:00
db:NVDid:CVE-2001-0054date:2001-02-16T05:00:00