CVE-2001-1386

WFTPD 3.00 allows remote attackers to read arbitrary files by uploading a (link) file that ends in a ".lnk." extension, which bypasses WFTPD's check for a ".lnk" extension.

Scoring

CVSS base score
0.04
EPSS probability
0.73%
Published
2004-09-01
Last modified
2026-03-16

Affected products

Markdown version · Browse all CVEs