Moderate severityNVD Advisory· Published Oct 19, 2010· Updated Apr 29, 2026
CVE-2008-7262
CVE-2008-7262
Description
Multiple directory traversal vulnerabilities in FTPServer.py in pyftpdlib before 0.3.0 allow remote authenticated users to access arbitrary files and directories via vectors involving a symlink in a pathname to a (1) CWD, (2) DELE, (3) STOR, or (4) RETR command.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
pyftpdlibPyPI | < 0.3.0 | 0.3.0 |
Affected products
3Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- github.com/advisories/GHSA-jw88-wxv5-7c4fghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2008-7262ghsaADVISORY
- code.google.com/p/pyftpdlib/issues/detailnvdWEB
- code.google.com/p/pyftpdlib/source/browse/trunk/HISTORYnvdWEB
- github.com/giampaolo/pyftpdlib/issues/55ghsaWEB
- github.com/pypa/advisory-database/tree/main/vulns/pyftpdlib/PYSEC-2010-4.yamlghsaWEB
News mentions
0No linked articles in our index yet.