Back
CVE-2004-0676
Directory traversal vulnerability in Fastream NETFile FTP/Web Server 6.7.2.1085 and earlier allows remote attackers to create or delete arbitrary files via .. (dot dot) and // (double slash) sequences in the filename parameter.
Published: Aug 6, 2004
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (3)
| Vendor | Product | Version |
|---|---|---|
| fastream | netfile_ftp_web_server | 6.5.1.980 |
| fastream | netfile_ftp_web_server | 6.5.1.981 |
| fastream | netfile_ftp_web_server | 6.7.2.1085 |
GitHub Security Advisory GHSA-g726-rjgf-ww3c
Directory traversal vulnerability in Fastream NETFile FTP/Web Server 6.7.2.1085 and earlier...
References (8)
- http://marc.info/?l=bugtraq&m=108904874104880&w=2
- http://www.haxorcitos.com/Fastream_advisory.txt URL Repurposed
- http://www.securityfocus.com/bid/10658 Exploit, Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16613
- http://marc.info/?l=bugtraq&m=108904874104880&w=2
- http://www.haxorcitos.com/Fastream_advisory.txt URL Repurposed
- http://www.securityfocus.com/bid/10658 Exploit, Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16613
Risk Scores
CVSS Score
10.0 / 10
EPSS Score
4.29%
Top 10% most likely to be exploited
Threat Score
41.3 / 100
Data Sources
NVD
EPSS
GitHub