CVE-2001-0582 describes a local file access vulnerability in Ben Spink CrushFTP FTP Server version 2.1.6 and earlier. An attacker can exploit this flaw by using directory traversal sequences (e.g., '..') within FTP commands like GET, CD, or RETR to access arbitrary files on the system. Rated Medium with a CVSS score of 4.6 (AV:L/AC:L/Au:N/C:P/I:P/A:P), this vulnerability requires local access and could lead to unauthorized disclosure, modification, or deletion of files. There is no evidence of active exploitation, nor are there publicly available Metasploit or ExploitDB modules, though it has garnered significant community discussion on platforms like GitHub.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.1.6CPE matchmatch criteria | cpe:2.3:a:ben_spink:crushftp_ftp_server:*:*:*:*:*:*:*:* | ||
2.1.4CPE matchmatch criteria | cpe:2.3:a:ben_spink:crushftp_ftp_server:2.1.4:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.