peter bassill · operator
$ cve CVE-2004-2487 JSON

CVE-2004-2487 EXPLOIT

4.0
MEDIUM · CVSS 2.0 · EPSS 3% (pctl 87)

Patch early

A public exploit exists.

Description

Directory traversal vulnerability in Nexgen FTP Server before 2.2.3.23 allows remote authenticated users to read or list arbitrary files via (1) "..", (2) "\..\" (backslash dot dot), or (3) "/../" sequences in (a) RETR (get), (b) NLST (ls), (c) LIST (ls), (d) RNFR, or (e) RNTO FTP commands.

Scoring

CVSS4.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:S/C:P/I:N/A:N
EPSS2.97% — more likely to be exploited than 87% of all CVEs
On CISA KEVno
Public exploityes
Published2004-12-31
Last modified2026-06-16

Affected (1)

VendorProduct
nexgennexgen ftp server

Public exploits

SourceTitleDate
exploit-dbNexGen FTP Server 1.0/2.x - Directory Traversal2004-03-24

References

→ the Explorer  ·  watch your stack  ·  NVD