CVE Database · CVE-2009-5012
CVSS v3.1
N/A
EPSS
1.03%
Published
Oct 19, 2010
Modified
Apr 28, 2026
Public PoC / Exploit (1)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
ftpserver.py in pyftpdlib before 0.5.2 does not require the l permission for the MLST command, which allows remote authenticated users to bypass intended access restrictions and list the root directory via an FTP session.
Weaknesses (CWE)
Affected Products (7)
References (8)