CVE-2005-2126

Description

The FTP client in Windows XP SP1 and Server 2003, and Internet Explorer 6 SP1 on Windows 2000 SP4, when Enable Folder View for FTP Sites is enabled and the user manually initiates a file transfer, allows user-assisted, remote FTP servers to overwrite files in arbitrary locations via crafted filenames.

Risk Information

Base Score
9.1
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS Score
Exploitation Probability
50.079

Associated Vulnerability

VulnerabilityOS Platform
Security Update for Windows Server 2003 (KB905495)Windows
Security Update for Internet Explorer 6 Service Pack 1 for Windows 2000 Service Pack 4 (KB905495)Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234