Show filters
76 Total Results
Displaying 21-30 of 76
Sort by:
Attacker Value
Unknown

CVE-2010-4871

Disclosure Date: October 07, 2011 (last updated October 04, 2023)
Unspecified vulnerability in SmartFTP before 4.0 Build 1142 allows attackers to have an unknown impact via a long filename.
0
Attacker Value
Unknown

CVE-2010-4790

Disclosure Date: April 27, 2011 (last updated October 04, 2023)
Directory traversal vulnerability in FilterFTP 2.0.3, 2.0.5, and probably earlier versions, allows remote FTP servers to write arbitrary files via a "..\" (dot dot backslash) in a filename. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2004-2769

Disclosure Date: July 02, 2010 (last updated October 04, 2023)
Cerberus FTP Server before 4.0.3.0 allows remote authenticated users to list hidden files, even when the "Display hidden files" option is enabled, via the (1) MLSD or (2) MLST commands.
0
Attacker Value
Unknown

CVE-2010-2428

Disclosure Date: June 24, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in admin_loginok.html in the Administrator web interface in Wing FTP Server for Windows 3.5.0 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted POST request.
0
Attacker Value
Unknown

CVE-2010-2425

Disclosure Date: June 24, 2010 (last updated October 04, 2023)
Directory traversal vulnerability in TitanFTPd in South River Technologies Titan FTP Server 8.10.1125, and probably earlier versions, allows remote authenticated users to read or delete arbitrary files via "..//" sequences in a COMB command.
0
Attacker Value
Unknown

CVE-2010-2426

Disclosure Date: June 24, 2010 (last updated October 04, 2023)
Directory traversal vulnerability in TitanFTPd in South River Technologies Titan FTP Server 8.10.1125, and probably earlier versions, allows remote authenticated users to read arbitrary files, determine file size, via "..//" sequences in the xcrc command.
0
Attacker Value
Unknown

CVE-2009-4795

Disclosure Date: April 22, 2010 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in Xlight FTP Server before 3.2.1, when ODBC authentication is enabled, allow remote attackers to execute arbitrary SQL commands via the (1) USER (aka username) or (2) PASS (aka password) command.
0
Attacker Value
Unknown

CVE-2008-5692

Disclosure Date: December 19, 2008 (last updated October 04, 2023)
Ipswitch WS_FTP Server Manager before 6.1.1, and possibly other Ipswitch products, allows remote attackers to bypass authentication and read logs via a logLogout action to FTPLogServer/login.asp followed by a request to FTPLogServer/LogViewer.asp with the localhostnull account name.
0
Attacker Value
Unknown

CVE-2008-5693

Disclosure Date: December 19, 2008 (last updated October 04, 2023)
Ipswitch WS_FTP Server Manager 6.1.0.0 and earlier, and possibly other Ipswitch products, might allow remote attackers to read the contents of custom ASP files in WSFTPSVR/ via a request with an appended dot character.
0
Attacker Value
Unknown

CVE-2008-5124

Disclosure Date: November 18, 2008 (last updated October 04, 2023)
JSCAPE Secure FTP Applet 4.8.0 and earlier does not ask the user to verify a new or mismatched SSH host key, which makes it easier for remote attackers to perform man-in-the-middle attacks.
0