CVE-2010-2695
Estado: ModificadaMedia (6.5)—
Directory traversal vulnerability in the SFTP/SSH2 virtual server in Xlight FTP Server 3.5.0, 3.5.5, and possibly other versions before 3.6 allows remote authenticated users to read, overwrite, or delete arbitrary files via .. (dot dot) sequences in the (1) ls, (2) rm, (3) rename, and other unspecified commands.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P
- Puntuación base: 6.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.88%
- Percentil entre todas las CVEs puntuadas: 79
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-22
Referencias
- http://osvdb.org/66037
- http://secunia.com/advisories/40473
- http://www.securityfocus.com/archive/1/512192/100/0/threaded
- http://www.xlightftpd.com/whatsnew.htm
- https://exchange.xforce.ibmcloud.com/vulnerabilities/60151
- http://osvdb.org/66037
- http://secunia.com/advisories/40473
- http://www.securityfocus.com/archive/1/512192/100/0/threaded
- http://www.xlightftpd.com/whatsnew.htm
- https://exchange.xforce.ibmcloud.com/vulnerabilities/60151
JSON original (NVD)
Mostrar
{
"id": "CVE-2010-2695",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
"authentication": "SINGLE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2010-07-12T17:30:02.767",
"references": [
{
"url": "http://osvdb.org/66037",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/40473",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/512192/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.xlightftpd.com/whatsnew.htm",
"tags": [
"Patch"
],
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/60151",
"source": "cve@mitre.org"
},
{
"url": "http://osvdb.org/66037",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/40473",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/512192/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.xlightftpd.com/whatsnew.htm",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/60151",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-22"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Directory traversal vulnerability in the SFTP/SSH2 virtual server in Xlight FTP Server 3.5.0, 3.5.5, and possibly other versions before 3.6 allows remote authenticated users to read, overwrite, or delete arbitrary files via .. (dot dot) sequences in the (1) ls, (2) rm, (3) rename, and other unspecified commands."
},
{
"lang": "es",
"value": "Vulnerabilidad de salto de directorio en SFTP/SSH2 virtual server en Xlight FTP Server v3.5.0, v3.5.5, y posiblemente otras versiones anteriores a v3.6 permite a atacantes remotos autenticados leer, sobreescribir o eliminar ficheros arbitrarios mediante secuencias .. (punto punto) en (1) ls, (2) rm, (3) rename y otros otros comandos no especificados"
}
],
"lastModified": "2026-06-16T23:21:20.540",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:xlightftpd:xlight_ftp_server:3.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2E58D1D4-5895-4FDC-B12F-AF289077ABC7"
},
{
"criteria": "cpe:2.3:a:xlightftpd:xlight_ftp_server:3.5.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9E1F5820-9FD7-4851-8798-A2D66C5ABCF3"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}