Vulnerability Name: | CVE-2005-2126 (CCN-18723) | ||||||||||||||||
Assigned: | 2005-01-01 | ||||||||||||||||
Published: | 2005-01-01 | ||||||||||||||||
Updated: | 2018-10-12 | ||||||||||||||||
Summary: | The FTP client in Windows XP SP1 and Server 2003, and Internet Explorer 6 SP1 on Windows 2000 SP4, when "Enable Folder View for FTP Sites" is enabled and the user manually initiates a file transfer, allows user-assisted, remote FTP servers to overwrite files in arbitrary locations via crafted filenames. | ||||||||||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||||||||||
CVSS v2 Severity: | 2.6 Low (CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N)
| ||||||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||
References: | Source: CCN Type: BugTraq Mailing List, Thu Dec 30 2004 - 08:56:41 CST 7a69Adv#17 - Internet Explorer FTP download path disclosure Source: MITRE Type: CNA CVE-2004-1376 Source: MITRE Type: CNA CVE-2005-2126 Source: CCN Type: SA13704 Internet Explorer FTP Download Directory Traversal Source: CCN Type: SA17163 Microsoft Windows FTP Client Filename Validation Vulnerability Source: SECUNIA Type: Patch, Vendor Advisory 17163 Source: CCN Type: SA17172 Avaya Various Products Multiple Vulnerabilities Source: SECUNIA Type: UNKNOWN 17172 Source: CCN Type: SA17223 Nortel Centrex IP Client Manager Multiple Vulnerabilities Source: SECUNIA Type: UNKNOWN 17223 Source: CCN Type: SECTRACK ID: 1015036 Microsoft Windows FTP Client Input Validation Hole Lets Remote Servers Create/Overwrite Files on the Target User`s System Source: SECTRACK Type: UNKNOWN 1015036 Source: CONFIRM Type: UNKNOWN http://support.avaya.com/elmodocs2/security/ASA-2005-214.pdf Source: CCN Type: US-CERT VU#415828 Microsoft Windows FTP client does not properly validate received file names Source: CERT-VN Type: Third Party Advisory, US Government Resource VU#415828 Source: CCN Type: Microsoft Security Bulletin MS05-044 Vulnerability in the Windows FTP Client Could Allow File Transfer Location Tampering (905495) Source: CCN Type: OSVDB ID: 12698 Microsoft IE FTP Download Traversal Arbitrary Command Execution Source: MISC Type: Patch http://www.securiteam.com/windowsntfocus/6M00I0KEAU.html Source: MS Type: UNKNOWN MS05-044 Source: XF Type: UNKNOWN ie-ftp-create-files(18723) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:1146 Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:1284 Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:1416 | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |