Filtered by vendor Cooolsoft Subscriptions
Total 9 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2003-0271 1 Cooolsoft 1 Personal Ftp Server 2024-11-20 N/A
Buffer overflow in Personal FTP Server allows remote attackers to execute arbitrary code via a long USER argument.
CVE-2002-1545 1 Cooolsoft 1 Personal Ftp Server 2024-11-20 N/A
CooolSoft Personal FTP Server 2.24 allows remote attackers to obtain the absolute pathname of the FTP root via a PWD command, which includes the full path in the response.
CVE-2002-1544 1 Cooolsoft 1 Personal Ftp Server 2024-11-20 N/A
Directory traversal vulnerability in CooolSoft Personal FTP Server 2.24 allows remote attackers to read or modify arbitrary files via .. (dot dot) sequences in the commands (1) LIST (ls), (2) mkdir, (3) put, or (4) get.
CVE-2002-1522 1 Cooolsoft 1 Powerftp 2024-11-20 N/A
Buffer overflow in PowerFTP FTP server 2.24, and possibly other versions, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long USER argument.
CVE-2002-0264 1 Cooolsoft 1 Powerftp 2024-11-20 N/A
PowerFTP Personal FTP Server 2.03 through 2.10 stores sensitive account information in plaintext in the ftpserver.ini file, which allows attackers with access to the file to gain privileges.
CVE-2001-0934 1 Cooolsoft 1 Powerftp 2024-11-20 N/A
Cooolsoft PowerFTP Server 2.03 allows remote attackers to obtain the physical path of the server root via the pwd command, which lists the full pathname.
CVE-2001-0933 1 Cooolsoft 1 Powerftp 2024-11-20 N/A
Cooolsoft PowerFTP Server 2.03 allows remote attackers to list the contents of arbitrary drives via a ls (LIST) command that includes the drive letter as an argument, e.g. "ls C:".
CVE-2001-0932 1 Cooolsoft 1 Powerftp 2024-11-20 N/A
Buffer overflow in Cooolsoft PowerFTP Server 2.03 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long command.
CVE-2001-0931 1 Cooolsoft 1 Powerftp 2024-11-20 N/A
Directory traversal vulnerability in Cooolsoft PowerFTP Server 2.03 allows attackers to list or read arbitrary files and directories via a .. (dot dot) in (1) LS or (2) GET.