Show filters
70 Total Results
Displaying 41-50 of 70
Sort by:
Attacker Value
Unknown
CVE-2018-19934
Disclosure Date: March 21, 2019 (last updated November 27, 2024)
SolarWinds Serv-U FTP Server 15.1.6.25 has reflected cross-site scripting (XSS) in the Web management interface via URL path and HTTP POST parameter.
0
Attacker Value
Unknown
CVE-2018-15906
Disclosure Date: March 21, 2019 (last updated November 27, 2024)
SolarWinds Serv-U FTP Server 15.1.6 allows remote authenticated users to execute arbitrary code by leveraging the Import feature and modifying a CSV file.
0
Attacker Value
Unknown
CVE-2018-10241
Disclosure Date: May 16, 2018 (last updated November 26, 2024)
A denial of service vulnerability in SolarWinds Serv-U before 15.1.6 HFv1 allows an authenticated user to crash the application (with a NULL pointer dereference) via a specially crafted URL beginning with the /Web%20Client/ substring.
0
Attacker Value
Unknown
CVE-2018-10240
Disclosure Date: May 16, 2018 (last updated November 26, 2024)
SolarWinds Serv-U MFT before 15.1.6 HFv1 assigns authenticated users a low-entropy session token that can be included in requests to the application as a URL parameter in lieu of a session cookie. This session token's value can be brute-forced by an attacker to obtain the corresponding session cookie and hijack the user's session.
0
Attacker Value
Unknown
CVE-2011-4800
Disclosure Date: December 14, 2011 (last updated October 04, 2023)
Directory traversal vulnerability in Serv-U FTP Server before 11.1.0.5 allows remote authenticated users to read and write arbitrary files, and list and create arbitrary directories, via a "..:/" (dot dot colon forward slash) in the (1) list, (2) put, or (3) get commands.
0
Attacker Value
Unknown
CVE-2009-4873
Disclosure Date: May 26, 2010 (last updated October 04, 2023)
Stack-based buffer overflow in the HTTP server in Rhino Software Serv-U Web Client 9.0.0.5 allows remote attackers to cause a denial of service (server crash) or execute arbitrary code via a long Session cookie.
0
Attacker Value
Unknown
CVE-2009-4815
Disclosure Date: April 27, 2010 (last updated October 04, 2023)
Directory traversal vulnerability in Serv-U before 9.2.0.1 allows remote authenticated users to read arbitrary files via unspecified vectors.
0
Attacker Value
Unknown
CVE-2009-4006
Disclosure Date: November 20, 2009 (last updated October 04, 2023)
Stack-based buffer overflow in the TEA decoding algorithm in RhinoSoft Serv-U FTP server 7.0.0.1, 9.0.0.5, and other versions before 9.1.0.0 allows remote attackers to execute arbitrary code via a long hexadecimal string.
0
Attacker Value
Unknown
CVE-2009-3655
Disclosure Date: October 09, 2009 (last updated October 04, 2023)
Rhino Software Serv-U 7.0.0.1 through 8.2.0.3 allows remote attackers to cause a denial of service (server crash) via unspecified vectors related to the "SITE SET TRANSFERPROGRESS ON" FTP command.
0
Attacker Value
Unknown
CVE-2009-1031
Disclosure Date: March 20, 2009 (last updated October 04, 2023)
Directory traversal vulnerability in the FTP server in Rhino Software Serv-U File Server 7.0.0.1 through 7.4.0.1 allows remote attackers to create arbitrary directories via a \.. (backslash dot dot) in an MKD request.
0