VYPR

Powerftp

by Cooolsoft

CVEs (6)

  • CVE-2001-0931Nov 28, 2001
    risk 0.06cvss epss 0.79

    Directory traversal vulnerability in Cooolsoft PowerFTP Server 2.03 allows attackers to list or read arbitrary files and directories via a .. (dot dot) in (1) LS or (2) GET.

  • CVE-2002-1522Apr 2, 2003
    risk 0.04cvss epss 0.15

    Buffer overflow in PowerFTP FTP server 2.24, and possibly other versions, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long USER argument.

  • CVE-2001-0932Nov 28, 2001
    risk 0.04cvss epss 0.10

    Buffer overflow in Cooolsoft PowerFTP Server 2.03 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long command.

  • CVE-2001-0933Nov 28, 2001
    risk 0.01cvss epss 0.09

    Cooolsoft PowerFTP Server 2.03 allows remote attackers to list the contents of arbitrary drives via a ls (LIST) command that includes the drive letter as an argument, e.g. "ls C:".

  • CVE-2002-0264May 29, 2002
    risk 0.00cvss epss 0.01

    PowerFTP Personal FTP Server 2.03 through 2.10 stores sensitive account information in plaintext in the ftpserver.ini file, which allows attackers with access to the file to gain privileges.

  • CVE-2001-0934Nov 28, 2001
    risk 0.00cvss epss 0.05

    Cooolsoft PowerFTP Server 2.03 allows remote attackers to obtain the physical path of the server root via the pwd command, which lists the full pathname.