Vulnerability Name:

CVE-2005-2126 (CCN-18723)

Assigned:2005-01-01
Published:2005-01-01
Updated:2018-10-12
Summary:The FTP client in Windows XP SP1 and Server 2003, and Internet Explorer 6 SP1 on Windows 2000 SP4, when "Enable Folder View for FTP Sites" is enabled and the user manually initiates a file transfer, allows user-assisted, remote FTP servers to overwrite files in arbitrary locations via crafted filenames.
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:2.6 Low (CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-Other
Vulnerability Consequences:Gain Access
References:Source: CCN
Type: BugTraq Mailing List, Thu Dec 30 2004 - 08:56:41 CST
7a69Adv#17 - Internet Explorer FTP download path disclosure

Source: MITRE
Type: CNA
CVE-2004-1376

Source: MITRE
Type: CNA
CVE-2005-2126

Source: CCN
Type: SA13704
Internet Explorer FTP Download Directory Traversal

Source: CCN
Type: SA17163
Microsoft Windows FTP Client Filename Validation Vulnerability

Source: SECUNIA
Type: Patch, Vendor Advisory
17163

Source: CCN
Type: SA17172
Avaya Various Products Multiple Vulnerabilities

Source: SECUNIA
Type: UNKNOWN
17172

Source: CCN
Type: SA17223
Nortel Centrex IP Client Manager Multiple Vulnerabilities

Source: SECUNIA
Type: UNKNOWN
17223

Source: CCN
Type: SECTRACK ID: 1015036
Microsoft Windows FTP Client Input Validation Hole Lets Remote Servers Create/Overwrite Files on the Target User`s System

Source: SECTRACK
Type: UNKNOWN
1015036

Source: CONFIRM
Type: UNKNOWN
http://support.avaya.com/elmodocs2/security/ASA-2005-214.pdf

Source: CCN
Type: US-CERT VU#415828
Microsoft Windows FTP client does not properly validate received file names

Source: CERT-VN
Type: Third Party Advisory, US Government Resource
VU#415828

Source: CCN
Type: Microsoft Security Bulletin MS05-044
Vulnerability in the Windows FTP Client Could Allow File Transfer Location Tampering (905495)

Source: CCN
Type: OSVDB ID: 12698
Microsoft IE FTP Download Traversal Arbitrary Command Execution

Source: MISC
Type: Patch
http://www.securiteam.com/windowsntfocus/6M00I0KEAU.html

Source: MS
Type: UNKNOWN
MS05-044

Source: XF
Type: UNKNOWN
ie-ftp-create-files(18723)

Source: OVAL
Type: UNKNOWN
oval:org.mitre.oval:def:1146

Source: OVAL
Type: UNKNOWN
oval:org.mitre.oval:def:1284

Source: OVAL
Type: UNKNOWN
oval:org.mitre.oval:def:1416

Vulnerable Configuration:Configuration 1:
  • cpe:/a:microsoft:ie:6.0:sp1:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/o:microsoft:windows_2000:*:sp4:*:fr:*:*:*:*
  • OR cpe:/o:microsoft:windows_2003_server:r2:*:*:*:*:*:*:*
  • OR cpe:/o:microsoft:windows_xp:*:sp1:tablet_pc:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:microsoft:ie:6.0:sp1:*:*:*:*:*:*
  • AND
  • cpe:/o:microsoft:windows_xp:-:sp1:*:*:*:*:*:*
  • OR cpe:/o:microsoft:windows_2000:-:sp4:*:*:*:*:*:*
  • OR cpe:/o:microsoft:windows_2003_server:-::~~~~itanium~:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.mitre.oval:def:1146
    V
    FTP Download Destination Tampering Vulnerability (Windows 2000)
    2014-02-24
    oval:org.mitre.oval:def:1416
    V
    FTP Download Destination Tampering Vulnerability (Windows XP)
    2011-05-16
    oval:org.mitre.oval:def:1284
    V
    FTP Download Destination Tampering Vulnerability (Server 2003)
    2011-05-09
    BACK
    microsoft ie 6.0 sp1
    microsoft windows 2000 * sp4
    microsoft windows 2003 server r2
    microsoft windows xp * sp1
    microsoft ie 6.0 sp1
    microsoft windows xp - sp1
    microsoft windows 2000 - sp4
    microsoft windows 2003 server -