Show filters
76 Total Results
Displaying 21-30 of 76
Sort by:
Attacker Value
Unknown
CVE-2010-4871
Disclosure Date: October 07, 2011 (last updated October 04, 2023)
Unspecified vulnerability in SmartFTP before 4.0 Build 1142 allows attackers to have an unknown impact via a long filename.
0
Attacker Value
Unknown
CVE-2010-4790
Disclosure Date: April 27, 2011 (last updated October 04, 2023)
Directory traversal vulnerability in FilterFTP 2.0.3, 2.0.5, and probably earlier versions, allows remote FTP servers to write arbitrary files via a "..\" (dot dot backslash) in a filename. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2004-2769
Disclosure Date: July 02, 2010 (last updated October 04, 2023)
Cerberus FTP Server before 4.0.3.0 allows remote authenticated users to list hidden files, even when the "Display hidden files" option is enabled, via the (1) MLSD or (2) MLST commands.
0
Attacker Value
Unknown
CVE-2010-2428
Disclosure Date: June 24, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in admin_loginok.html in the Administrator web interface in Wing FTP Server for Windows 3.5.0 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted POST request.
0
Attacker Value
Unknown
CVE-2010-2425
Disclosure Date: June 24, 2010 (last updated October 04, 2023)
Directory traversal vulnerability in TitanFTPd in South River Technologies Titan FTP Server 8.10.1125, and probably earlier versions, allows remote authenticated users to read or delete arbitrary files via "..//" sequences in a COMB command.
0
Attacker Value
Unknown
CVE-2010-2426
Disclosure Date: June 24, 2010 (last updated October 04, 2023)
Directory traversal vulnerability in TitanFTPd in South River Technologies Titan FTP Server 8.10.1125, and probably earlier versions, allows remote authenticated users to read arbitrary files, determine file size, via "..//" sequences in the xcrc command.
0
Attacker Value
Unknown
CVE-2009-4795
Disclosure Date: April 22, 2010 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in Xlight FTP Server before 3.2.1, when ODBC authentication is enabled, allow remote attackers to execute arbitrary SQL commands via the (1) USER (aka username) or (2) PASS (aka password) command.
0
Attacker Value
Unknown
CVE-2008-5692
Disclosure Date: December 19, 2008 (last updated October 04, 2023)
Ipswitch WS_FTP Server Manager before 6.1.1, and possibly other Ipswitch products, allows remote attackers to bypass authentication and read logs via a logLogout action to FTPLogServer/login.asp followed by a request to FTPLogServer/LogViewer.asp with the localhostnull account name.
0
Attacker Value
Unknown
CVE-2008-5693
Disclosure Date: December 19, 2008 (last updated October 04, 2023)
Ipswitch WS_FTP Server Manager 6.1.0.0 and earlier, and possibly other Ipswitch products, might allow remote attackers to read the contents of custom ASP files in WSFTPSVR/ via a request with an appended dot character.
0
Attacker Value
Unknown
CVE-2008-5124
Disclosure Date: November 18, 2008 (last updated October 04, 2023)
JSCAPE Secure FTP Applet 4.8.0 and earlier does not ask the user to verify a new or mismatched SSH host key, which makes it easier for remote attackers to perform man-in-the-middle attacks.
0