Security Advisory
CVE-2010-4149
CVE vulnerability detail - eXtreme Datacenter Security Operations
Description
Directory traversal vulnerability in FreshWebMaster Fresh FTP 5.36, 5.37, and possibly earlier, allows remote FTP servers to write arbitrary files via a "..\" (dot dot backslash) in a filename. NOTE: some of these details are obtained from third party information.