CVE detail
CVE-2010-2251 — CVE-2010-2251
Published 2010-07-06 · Modified 2026-06-16 · Vendor alexander_v._lukyanov · Product lftp · Source nvd
UNKNOWN
severity
CVSS-derived band
0.0363
EPSS probability
exploitation probability, 30d
88.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
The get1 command, as used by lftpget, in LFTP before 4.0.6 does not properly validate a server-provided filename before determining the destination filename of a download, which allows remote servers to create or overwrite arbitrary files via a Content-Disposition header that suggests a crafted filename, and possibly execute arbitrary code as a consequence of writing to a dotfile in a home directory.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References