Show filters
13 Total Results
Displaying 1-10 of 13
Sort by:
Attacker Value
Unknown

CVE-2017-17933

Disclosure Date: December 29, 2017 (last updated November 26, 2024)
cgi/surgeftpmgr.cgi (aka the Web Manager interface on TCP port 7021 or 9021) in NetWin SurgeFTP version 23f2 has XSS via the classid, domainid, or username parameter.
Attacker Value
Unknown

CVE-2013-4742

Disclosure Date: August 09, 2013 (last updated October 05, 2023)
Buffer overflow in NetWin SurgeFTP before 23d2 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long string within the authentication request.
0
Attacker Value
Unknown

CVE-2010-1068

Disclosure Date: March 23, 2010 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in surgeftpmgr.cgi in NetWin SurgeFTP 2.3a6 allow remote attackers to inject arbitrary web script or HTML via the (1) domainid or (2) classid parameter in a class action.
0
Attacker Value
Unknown

CVE-2008-1052

Disclosure Date: February 27, 2008 (last updated October 04, 2023)
The administration web interface in NetWin SurgeFTP 2.3a2 and earlier allows remote attackers to cause a denial of service (daemon crash) via a large integer in the Content-Length HTTP header, which triggers a NULL pointer dereference when memory allocation fails.
0
Attacker Value
Unknown

CVE-2007-3768

Disclosure Date: July 15, 2007 (last updated October 04, 2023)
The mirror mechanism in SurgeFTP 2.3a1 allows user-assisted, remote FTP servers to cause a denial of service (restart) via a malformed response to a PASV command.
0
Attacker Value
Unknown

CVE-2007-3769

Disclosure Date: July 15, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the mirrored server management interface in SurgeFTP 2.3a1 allows user-assisted, remote FTP servers to inject arbitrary web script or HTML via a malformed response without a status code, which is reflected to the user in the resulting error message. NOTE: this can be leveraged for root access via a sequence of steps involving web script that creates a new FTP user account.
0
Attacker Value
Unknown

CVE-2005-1034

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
SurgeFTP 2.2m1 allows remote attackers to cause a denial of service (application hang) via the LEAK command.
0
Attacker Value
Unknown

CVE-2001-0697

Disclosure Date: September 20, 2001 (last updated February 22, 2025)
NetWin SurgeFTP prior to 1.1h allows a remote attacker to cause a denial of service (crash) via an 'ls ..' command.
0
Attacker Value
Unknown

CVE-2001-0698

Disclosure Date: September 20, 2001 (last updated February 22, 2025)
Directory traversal vulnerability in NetWin SurgeFTP 2.0a and 1.0b allows a remote attacker to list arbitrary files and directories via the 'nlist ...' command.
0
Attacker Value
Unknown

CVE-2001-0696

Disclosure Date: September 20, 2001 (last updated February 22, 2025)
NetWin SurgeFTP 2.0a and 1.0b allows a remote attacker to cause a denial of service (crash) via a CD command to a directory with an MS-DOS device name such as con.
0