FTP vulnerabilities

Showing 101 - 108 of 108 CVEs

  1. CVE-2020-15543 Published Jul 5, 2020

    SolarWinds Serv-U FTP server before 15.2.1 does not validate an argument path.

  2. CVE-2020-14057 Published Jul 1, 2020

    Monsta FTP 2.10.1 or below allows external control of paths used in filesystem operations. This allows attackers to read and write arbitrary local files, allowing an attacker to gain remote code execution in common deployments.

  3. CVE-2020-14056 Published Jul 1, 2020

    Monsta FTP 2.10.1 or below is prone to a server-side request forgery vulnerability due to insufficient restriction of the web fetch functionality. This allows attackers to read arbitrary local files and interact with arbitrary third-party services.

  4. CVE-2020-14055 Published Jul 1, 2020

    Monsta FTP 2.10.1 or below is prone to a stored cross-site scripting vulnerability in the language setting due to insufficient output encoding.

  5. CVE-2020-9365 Published Feb 24, 2020

    An issue was discovered in Pure-FTPd 1.0.49. An out-of-bounds (OOB) read has been detected in the pure_strcmp function in utils.c.

  6. CVE-2020-9273 Published Feb 20, 2020

    In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the data transfer channel. This triggers a use-after-free in alloc_pool in pool.c, and possible remote code execution.

  7. CVE-2020-6857 Published Jan 21, 2020

    CarbonFTP v1.4 uses insecure proprietary password encryption with a hard-coded weak encryption key. The key for local FTP server passwords is hard-coded in the binary.

  8. CVE-2020-5196 Published Jan 14, 2020

    Cerberus FTP Server Enterprise Edition prior to versions 11.0.3 and 10.0.18 allows an authenticated attacker to create files, display hidden files, list directories, and list files without the permission to zip and download (or unzip and upload) files. There are multiple ways to bypass certain permissions by utilizing the zip and unzip features. As a result, users without permission can see files, folders, and hidden files, and can create directories without permission.