peter bassill · operator
$ cve CVE-2001-0283 JSON

CVE-2001-0283 EXPLOIT

6.4
MEDIUM · CVSS 2.0 · EPSS 6% (pctl 93)

Patch early

A public exploit exists.

Description

Directory traversal vulnerability in SunFTP build 9 allows remote attackers to read arbitrary files via .. (dot dot) characters in various commands, including (1) GET, (2) MKDIR, (3) RMDIR, (4) RENAME, or (5) PUT.

Scoring

CVSS6.4 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
EPSS6% — more likely to be exploited than 93% of all CVEs
On CISA KEVno
Public exploityes
Published2001-05-03
Last modified2026-06-16

Affected (1)

VendorProduct
sunsun ftp

Public exploits

SourceTitleDate
exploit-dbSunFTP 1.0 Build 9 - Unauthorized File Access2001-03-02

References

→ the Explorer  ·  watch your stack  ·  NVD