Vulnerability record · CVE-2005-0483 · published 30 March 2005
CVE-2005-0483: Glftpd vulnerability
Glftpd · Glftpd
Multiple directory traversal vulnerabilities in sitenfo.sh, sitezipchk.sh, and siteziplist.sh in Glftpd 1.26 to 2.00 allow remote authenticated users to (1) determine the existence of arbitrary files, (2) list files in restricted directories, or (3) read arbitrary files from within ZIP or gzip files, via .. (dot dot) sequences and globbing ("*") characters in a SITE NFO command.
Description
Multiple directory traversal vulnerabilities in sitenfo.sh, sitezipchk.sh, and siteziplist.sh in Glftpd 1.26 to 2.00 allow remote authenticated users to (1) determine the existence of arbitrary files, (2) list files in restricted directories, or (3) read arbitrary files from within ZIP or gzip files, via .. (dot dot) sequences and globbing ("*") characters in a SITE NFO command.
AV:N/AC:L/Au:N/C:P/I:N/A:N
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/archive/1/390924 | ExploitVendor Advisory |
| http://www.securityfocus.com/bid/12586 | ExploitVendor Advisory |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/19401 | |
| http://www.securityfocus.com/archive/1/390924 | ExploitVendor Advisory |
| http://www.securityfocus.com/bid/12586 | ExploitVendor Advisory |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/19401 |
Track CVE-2005-0483 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2005-0483), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.