Vulnerabilities (CVE)

Filtered by vendor Wftpserver Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2015-4108 1 Wftpserver 1 Wing Ftp Server 2018-10-09 6.8 MEDIUM N/A
Multiple cross-site request forgery (CSRF) vulnerabilities in Wing FTP Server before 4.4.7 allow remote attackers to hijack the authentication of administrators for requests that (1) execute arbitrary code via a crafted request to admin_lua_script.html or (2) add a domain administrator via a crafted request to admin_addadmin.html.
CVE-2009-0351 1 Wftpserver 1 Winftp Ftp Server 2017-09-29 9.0 HIGH N/A
Stack-based buffer overflow in WFTPSRV.exe in WinFTP 2.3.0 allows remote authenticated users to execute arbitrary code via a long LIST argument beginning with an * (asterisk) character.
CVE-2008-5666 1 Wftpserver 1 Winftp Ftp Server 2017-09-29 3.5 LOW N/A
WinFTP FTP Server 2.3.0, when passive (aka PASV) mode is used, allows remote authenticated users to cause a denial of service via a sequence of FTP sessions that include an invalid "NLST -1" command.
CVE-2010-2428 2 Microsoft, Wftpserver 2 Windows, Wing Ftp Server 2017-08-17 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in admin_loginok.html in the Administrator web interface in Wing FTP Server for Windows 3.5.0 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted POST request.
CVE-2012-4729 1 Wftpserver 1 Wing Ftp Server 2013-03-02 6.8 MEDIUM N/A
Wing FTP Server before 4.1.1 allows remote authenticated users to cause a denial of service (daemon crash) via two zip commands.