Vulnerabilities (CVE)

Filtered by vendor Wftpserver Subscribe
Total 22 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-8634 1 Wftpserver 1 Wing Ftp Server 2024-11-21 7.2 HIGH 7.8 HIGH
Wing FTP Server v6.2.3 for Linux, macOS, and Solaris sets insecure permissions on files modified within the HTTP file management interface, resulting in files being saved with world-readable and world-writable permissions. If a sensitive system file were edited this way, a low-privilege user may escalate privileges to root.
CVE-2020-27735 1 Wftpserver 1 Wing Ftp Server 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
An XSS issue was discovered in Wing FTP 6.4.4. An arbitrary IFRAME element can be included in the help pages via a crafted link, leading to the execution of (sandboxed) arbitrary HTML and JavaScript in the user's browser.