Medium severity5.3NVD Advisory· Published Mar 22, 2019· Updated Jun 17, 2026
CVE-2019-9649
CVE-2019-9649
Description
An issue was discovered in the SFTP Server component in Core FTP 2.0 Build 674. Using the MDTM FTP command, a remote attacker can use a directory traversal technique (..\..\) to browse outside the root directory to determine the existence of a file on the operating system, and its last modified date.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: = 2.0 Build 674
Patches
Vulnerability mechanics
References
6- seclists.org/fulldisclosure/2019/Mar/25nvdExploitMailing ListThird Party Advisory
- www.exploit-db.com/exploits/46534nvdExploitThird Party AdvisoryVDB Entry
- www.coreftp.com/forums/viewtopic.phpnvdProductVendor Advisory
- www.securityfocus.com/bid/107449nvdThird Party AdvisoryVDB Entry
- packetstormsecurity.com/files/154205/CoreFTP-Server-MDTM-Directory-Traversal.htmlnvd
- seclists.org/fulldisclosure/2019/Aug/22nvd
News mentions
0No linked articles in our index yet.