Show filters
76 Total Results
Displaying 1-10 of 76
Sort by:
Attacker Value
Unknown
CVE-2010-2251
Disclosure Date: July 06, 2010 (last updated October 04, 2023)
The get1 command, as used by lftpget, in LFTP before 4.0.6 does not properly validate a server-provided filename before determining the destination filename of a download, which allows remote servers to create or overwrite arbitrary files via a Content-Disposition header that suggests a crafted filename, and possibly execute arbitrary code as a consequence of writing to a dotfile in a home directory.
1
Attacker Value
Unknown
CVE-2024-0889
Disclosure Date: January 25, 2024 (last updated February 03, 2024)
A vulnerability was found in Kmint21 Golden FTP Server 2.02b and classified as problematic. This issue affects some unknown processing of the component PASV Command Handler. The manipulation leads to denial of service. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-252041 was assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2024-0732
Disclosure Date: January 19, 2024 (last updated January 27, 2024)
A vulnerability was found in PCMan FTP Server 2.0.7 and classified as problematic. This issue affects some unknown processing of the component STOR Command Handler. The manipulation leads to denial of service. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-251555.
0
Attacker Value
Unknown
CVE-2024-0731
Disclosure Date: January 19, 2024 (last updated January 27, 2024)
A vulnerability has been found in PCMan FTP Server 2.0.7 and classified as problematic. This vulnerability affects unknown code of the component PUT Command Handler. The manipulation leads to denial of service. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-251554 is the identifier assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2024-0693
Disclosure Date: January 18, 2024 (last updated February 01, 2024)
A vulnerability classified as problematic was found in EFS Easy File Sharing FTP 2.0. Affected by this vulnerability is an unknown functionality. The manipulation of the argument username leads to denial of service. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-251479. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown
CVE-2021-4432
Disclosure Date: January 16, 2024 (last updated January 24, 2024)
A vulnerability was found in PCMan FTP Server 2.0.7. It has been classified as problematic. This affects an unknown part of the component USER Command Handler. The manipulation leads to denial of service. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-250719.
0
Attacker Value
Unknown
CVE-2022-22899
Disclosure Date: February 17, 2022 (last updated February 23, 2025)
Core FTP / SFTP Server v2 Build 725 was discovered to allow unauthenticated attackers to cause a Denial of Service (DoS) via a crafted packet through the SSH service.
0
Attacker Value
Unknown
CVE-2020-19595
Disclosure Date: April 05, 2021 (last updated February 22, 2025)
Buffer overflow vulnerability in Core FTP Server v2 Build 697, via a crafted username.
0
Attacker Value
Unknown
CVE-2019-9649
Disclosure Date: March 22, 2019 (last updated November 27, 2024)
An issue was discovered in the SFTP Server component in Core FTP 2.0 Build 674. Using the MDTM FTP command, a remote attacker can use a directory traversal technique (..\..\) to browse outside the root directory to determine the existence of a file on the operating system, and its last modified date.
0
Attacker Value
Unknown
CVE-2019-9648
Disclosure Date: March 22, 2019 (last updated November 27, 2024)
An issue was discovered in the SFTP Server component in Core FTP 2.0 Build 674. A directory traversal vulnerability exists using the SIZE command along with a \..\..\ substring, allowing an attacker to enumerate file existence based on the returned information.
0