← Vulnerability feed

Vulnerability record · CVE-2008-4501 · published 9 October 2008

CVE-2008-4501: Solarwinds serv-u file server path traversal vulnerability

Solarwinds · Serv U File Server

Directory traversal vulnerability in the FTP server in Serv-U 7.0.0.1 through 7.3, including 7.2.0.1, allows remote authenticated users to overwrite or create arbitrary files via a ..\ (dot dot backslash) in the RNTO command.

9.0 CVSS 2.0 High EPSS 11% · top 4.3% CWE-22 · Path traversal
9.0CVSS 2.0 base score
11%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
16 Jun 2026Last modified by NVD

Description

Directory traversal vulnerability in the FTP server in Serv-U 7.0.0.1 through 7.3, including 7.2.0.1, allows remote authenticated users to overwrite or create arbitrary files via a ..\ (dot dot backslash) in the RNTO command.

AV:N/AC:L/Au:S/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2008-4501 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2009-4006Serv-U FTP Server TEA Decoding Stack Buffer OverflowRhinoSoft Serv-U FTP server versions before 9.1.0.0 contain a stack-based buffer overflow in the TEA decoding algorithm. A remote attacker can trigge…EPSS 83%analysed10.0CVE-2004-2532Solarwinds serv-u file server vulnerabilityServ-U FTP server before 5.1.0.0 has a default account and password for local administration, which allows local users to execute arbitrary commands …EPSS 15%10.0CVE-2004-0330Serv-U FTP MDTM time zone buffer overflow allows remote code executionServ-U FTP versions before 5.0.0.4 contain a buffer overflow in the handling of the time zone argument to the MDTM command. A remote authenticated FT…EPSS 85%analysed9.0CVE-2011-4800Solarwinds serv-u file server path traversal vulnerabilityDirectory traversal vulnerability in Serv-U FTP Server before 11.1.0.5 allows remote authenticated users to read and write arbitrary files, and list …EPSS 7.3%8.5CVE-2004-2111Serv-U FTP Server site chmod stack buffer overflowServ-U FTP Server before 4.2 has a stack-based buffer overflow in the site chmod command, triggered by a long filename. A remote attacker who can iss…EPSS 87%analysed7.8CVE-2009-1031Solarwinds serv-u file server path traversal vulnerabilityDirectory traversal vulnerability in the FTP server in Rhino Software Serv-U File Server 7.0.0.1 through 7.4.0.1 allows remote attackers to create ar…EPSS 11%7.5CVE-2001-1463Solarwinds serv-u file server vulnerabilityThe remote administration client for RhinoSoft Serv-U 3.0 sends the user password in plaintext even when S/KEY One-Time Password (OTP) authentication…EPSS 3.2%6.1CVE-2021-25179Solarwinds serv-u file server cross-site scripting vulnerabilitySolarWinds Serv-U before 15.2 is affected by Cross Site Scripting (XSS) via the HTTP Host header.EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2008-4501), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.