CVE-2008-2795 EXPLOIT
4.3
MEDIUM · CVSS 2.0 · EPSS 9.5% (pctl 95)
Patch early
A public exploit exists.
Description
Directory traversal vulnerability in the FTP and SFTP clients in IDM Computer Solutions Inc UltraEdit 14.00b allows remote FTP servers to create or overwrite arbitrary files via a .. (dot dot) or a ..\ (dot dot backslash) in a response to a LIST command.
Scoring
| CVSS | 4.3 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
| EPSS | 9.53% — more likely to be exploited than 95% of all CVEs |
| Weakness | CWE-22 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2008-06-20 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| idm computer solutions inc | ultraedit |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | UltraEdit 14.00b - FTP/SFTP 'LIST' Directory Traversal | 2008-06-17 |
References
- http://secunia.com/advisories/30749
- http://vuln.sg/ultraedit1400b-en.html
- http://www.securityfocus.com/bid/29784
- http://www.vupen.com/english/advisories/2008/1864/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43149
- http://secunia.com/advisories/30749
- http://vuln.sg/ultraedit1400b-en.html
- http://www.securityfocus.com/bid/29784
- http://www.vupen.com/english/advisories/2008/1864/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43149
→ the Explorer · watch your stack · NVD