Directory traversal vulnerability in the third party tool from Raz-Lee, as used to secure the iSeries AS/400 FTP server, allows remote attackers to access arbitrary files, including those from qsys.lib, via ".." sequences in a GET request. Fix is available on http://www.razlee.com/
Publication date: Mon, 02 May 2005 09:00:00 +0000