CVE-2007-4756

Directory traversal vulnerability in the FTP client in Total Commander before 7.02 allows remote FTP servers to create or overwrite arbitrary files via ".." (dot dot backslash) sequences in a filename. NOTE: the ".." are not displayed when the user lists files. NOTE: this can be leveraged for code execution by writing to a Startup folder.
Configurations

Configuration 1

cpe:2.3:a:ghisler:total_commander:*:*:*:*:*:*:*:*

Information

Published : 2007-09-08 01:17

Updated : 2018-10-15 09:37


NVD link : CVE-2007-4756

Mitre link : CVE-2007-4756

Products Affected
No products.
CWE