Vulnonym.org

CVE-2005-0483 - Dearest Phase

Description

Multiple directory traversal vulnerabilities in sitenfo.sh sitezipchk.sh and siteziplist.sh in Glftpd 1.26 to 2.00 allow remote authenticated users to (1) determine the existence of arbitrary files (2) list files in restricted directories or (3) read arbitrary files from within ZIP or gzip files via .. (dot dot) sequences and globbing (\) characters in a SITE NFO command.

Reference

http://www.securityfocus.com/archive/1/390924 http://www.securityfocus.com/bid/12586 https://exchange.xforce.ibmcloud.com/vulnerabilities/19401