CVE-2014-1843 EXPLOIT
5.0
MEDIUM · CVSS 2.0 · EPSS 4.7% (pctl 91)
Patch early
A public exploit exists.
Description
Directory traversal vulnerability in the web interface in Titan FTP Server before 10.40 build 1829 allows remote attackers to obtain the property information of an arbitrary home folder via a Properties action with a .. (dot dot) in the src parameter.
Scoring
| CVSS | 5.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
| EPSS | 4.67% — more likely to be exploited than 91% of all CVEs |
| Weakness | CWE-22 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2014-04-29 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| southrivertech | titan ftp server |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Titan FTP Server 10.32 Build 1816 - Directory Traversal | 2014-02-11 |
References
- http://archives.neohapsis.com/archives/fulldisclosure/2014-02/0092.html
- http://www.exploit-db.com/exploits/31579
- http://www.osvdb.org/103197
- http://www.securityfocus.com/bid/65469
- http://archives.neohapsis.com/archives/fulldisclosure/2014-02/0092.html
- http://www.exploit-db.com/exploits/31579
- http://www.osvdb.org/103197
- http://www.securityfocus.com/bid/65469
→ the Explorer · watch your stack · NVD