Back

CVE-2001-0054

Directory traversal vulnerability in FTP Serv-U before 2.5i allows remote attackers to escape the FTP root and read arbitrary files by appending a string such as "/..%20." to a CD command, a variant of a .. (dot dot) attack.

Published: Feb 16, 2001 Modified: Jun 16, 2026
CWE-22

CVSS Metrics

Affected Products (1)

Vendor Product Version
solarwinds serv-u_file_server 3.0.0.16

GitHub Security Advisory GHSA-rggv-4m8c-3m5j

Directory traversal vulnerability in FTP Serv-U before 2.5i allows remote attackers to escape the...

Risk Scores

CVSS Score 5.0 / 10
EPSS Score 12.05%

Top 4% most likely to be exploited

Threat Score 23.6 / 100

Data Sources

NVD EPSS GitHub