Unrated severityNVD Advisory· Published Jun 13, 2008· Updated Apr 23, 2026
CVE-2008-2702
CVE-2008-2702
Description
Directory traversal vulnerability in the FTP client in ALTools ESTsoft ALFTP 4.1 beta 2 and 5.0 allows remote FTP servers to create or overwrite arbitrary files via a .. (dot dot) in a response to a LIST command, a related issue to CVE-2002-1345. NOTE: this can be leveraged for code execution by writing to a Startup folder.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- vuln.sg/alftp41b2-en.htmlnvdExploitThird Party Advisory
- www.securityfocus.com/bid/29585nvdExploitThird Party AdvisoryVDB Entry
- secunia.com/advisories/30559nvdThird Party Advisory
- www.vupen.com/english/advisories/2008/1763/referencesnvdThird Party Advisory
- exchange.xforce.ibmcloud.com/vulnerabilities/42900nvdThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.