Vulnerability Report

CVE-2008-4501

Title: Solarwinds Serv-U File Server Path Traversal / LFI

Path Traversal / LFI

Proof Of Concept

PoC Available for CVE-2008-4501

CWE Category CWE-22
Published Date Oct 09, 2008
Modified Date Apr 09, 2025
Exploit Status Available
Score 9.0 CVSS v2.0
Exploit Probability (EPSS)
4.60%

Vulnerability Summary

CVE-2008-4501: Directory traversal vulnerability in the FTP server in Serv-U 7.0.0.1 through 7.3, including 7.2.0.1, allows remote authenticated users to overwrite or create arbitrary files via a ..\ (dot dot backslash) in the RNTO command.

CVSS v2.0
Source Entity [email protected]
Severity HIGH
9.0
Access Vector
N/A
Authentication
N/A
RAW VECTOR AV:N/AC:L/Au:S/C:C/I:C/A:C

Associated Attack Patterns (CAPEC)

Total: Patterns

CVE-2008-4501 Exploits & PoCs (Proof Of Concept)

Exploit-DB https://www.exploit-db.com/exploits/6661
View Code
MODIFIED

Vulnerability data or affected products updated.

PUBLISHED

Vulnerability first announced in NVD.

Attack Vector Matrix

Access Vector N/A
Complexity N/A
Privileges N/A
Interaction NONE
CVSS Vector String AV:N/AC:L/Au:S/C:C/I:C/A:C

Affected Stack

No specific products linked.