CVE-2004-2747

Directory traversal vulnerability in Pablo Software Solutions Quick ‘n Easy FTP Server 1.77, and possibly earlier versions, allows remote authenticated users to determine the existence of arbitrary files via a .. (dot dot) in the DEL command, which triggers different error messages depending on whether the file exists or not.

Date published : 2007-11-08

http://www.securityfocus.com/bid/9443

http://www.securityfocus.com/archive/1/350224/30/21640/threaded