{"id":"CVE-2015-7601","title":"Directory traversal vulnerability in PCMan's FTP Server 2.0.7 allows remote attackers to read arbitrary files via a ..// (dot dot double slash) in a RETR command.","summary":"Directory traversal vulnerability in PCMan's FTP Server 2.0.7 allows remote attackers to read arbitrary files via a ..// (dot dot double slash) in a RETR command.","severity":"high","cvss":7.8,"cvssVector":"AV:N/AC:L/Au:N/C:C/I:N/A:N","cwe":["CWE-22"],"vendor":"pcman","product":"ftp_server","affected":["ftp_server = 2.0.7"],"published":"2015-09-29","updated":"2026-08-19","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2015-7601","references":[{"url":"http://packetstormsecurity.com/files/133756/PCMan-FTP-Server-2.0.7-Directory-Traversal.html","label":"cve@mitre.org"},{"url":"https://www.exploit-db.com/exploits/38340/","label":"cve@mitre.org"},{"url":"http://packetstormsecurity.com/files/133756/PCMan-FTP-Server-2.0.7-Directory-Traversal.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.exploit-db.com/exploits/38340/","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","exploit-available"],"epss":0.58334,"epssPercentile":0.99078,"exploitAvailable":true,"ingestedAt":"2026-08-19T17:42:35.870Z","exploits":{"exploitdb":true,"metasploit":["auxiliary/scanner/ftp/pcman_ftp_traversal"],"checkedAt":"2026-09-21T15:23:33.927Z"},"slug":"CVE-2015-7601","body":"## Overview\n\nDirectory traversal vulnerability in PCMan's FTP Server 2.0.7 allows remote attackers to read arbitrary files via a ..// (dot dot double slash) in a RETR command.\n\n## Affected\n\n- `ftp_server = 2.0.7`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":67,"depthScoreParts":{"impact":42.9,"likelihood":11.7,"exploitation":12,"ransomware":0},"changes":[]}