Back

CVE-2005-0519

ArGoSoft FTP Server before 1.4.2.7 allows remote attackers to read arbitrary files by uploading a ZIP file containing a shortcut (.LNK) file, using SITE UNZIP to extract the .LNK file onto the server, then accessing the file, a different vulnerability than CVE-2005-0520.

Published: Feb 18, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (12)

Vendor Product Version
argosoft ftp_server 1.4.1.1
argosoft ftp_server 1.4.1.2
argosoft ftp_server 1.4.1.3
argosoft ftp_server 1.4.1.4
argosoft ftp_server 1.4.1.5
argosoft ftp_server 1.4.1.6
argosoft ftp_server 1.4.1.7
argosoft ftp_server 1.4.1.8
argosoft ftp_server 1.4.1.9
argosoft ftp_server 1.4.2
argosoft ftp_server 1.4.2.1
argosoft ftp_server 1.4.2.2

GitHub Security Advisory GHSA-mphq-qg37-mjrq

ArGoSoft FTP Server before 1.4.2.7 allows remote attackers to read arbitrary files by uploading a...

Risk Scores

CVSS Score 10.0 / 10
EPSS Score 3.78%

Top 11% most likely to be exploited

Threat Score 41.1 / 100

Data Sources

NVD EPSS GitHub