Back

CVE-2004-0676

Directory traversal vulnerability in Fastream NETFile FTP/Web Server 6.7.2.1085 and earlier allows remote attackers to create or delete arbitrary files via .. (dot dot) and // (double slash) sequences in the filename parameter.

Published: Aug 6, 2004 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (3)

Vendor Product Version
fastream netfile_ftp_web_server 6.5.1.980
fastream netfile_ftp_web_server 6.5.1.981
fastream netfile_ftp_web_server 6.7.2.1085

GitHub Security Advisory GHSA-g726-rjgf-ww3c

Directory traversal vulnerability in Fastream NETFile FTP/Web Server 6.7.2.1085 and earlier...

Risk Scores

CVSS Score 10.0 / 10
EPSS Score 4.29%

Top 10% most likely to be exploited

Threat Score 41.3 / 100

Data Sources

NVD EPSS GitHub