CVE-2012-10028
- EPSS 53.69%
- Veröffentlicht 05.08.2025 20:15:33
- Zuletzt bearbeitet 07.08.2025 16:15:29
Netwin SurgeFTP version 23c8 and prior contains a vulnerability in its web-based administrative console that allows authenticated users to execute arbitrary system commands via crafted POST requests to `surgeftpmgr.cgi`. This can lead to full remote ...
CVE-2017-17933
- EPSS 0.21%
- Veröffentlicht 29.12.2017 18:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
cgi/surgeftpmgr.cgi (aka the Web Manager interface on TCP port 7021 or 9021) in NetWin SurgeFTP version 23f2 has XSS via the classid, domainid, or username parameter.
CVE-2013-4742
- EPSS 3.71%
- Veröffentlicht 09.08.2013 21:55:07
- Zuletzt bearbeitet 11.04.2025 00:51:21
Buffer overflow in NetWin SurgeFTP before 23d2 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long string within the authentication request.
CVE-2010-1068
- EPSS 0.29%
- Veröffentlicht 23.03.2010 18:30:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple cross-site scripting (XSS) vulnerabilities in surgeftpmgr.cgi in NetWin SurgeFTP 2.3a6 allow remote attackers to inject arbitrary web script or HTML via the (1) domainid or (2) classid parameter in a class action.
CVE-2008-1052
- EPSS 6.98%
- Veröffentlicht 27.02.2008 19:44:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The administration web interface in NetWin SurgeFTP 2.3a2 and earlier allows remote attackers to cause a denial of service (daemon crash) via a large integer in the Content-Length HTTP header, which triggers a NULL pointer dereference when memory all...
CVE-2007-3768
- EPSS 0.99%
- Veröffentlicht 15.07.2007 21:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The mirror mechanism in SurgeFTP 2.3a1 allows user-assisted, remote FTP servers to cause a denial of service (restart) via a malformed response to a PASV command.
CVE-2007-3769
- EPSS 0.74%
- Veröffentlicht 15.07.2007 21:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in the mirrored server management interface in SurgeFTP 2.3a1 allows user-assisted, remote FTP servers to inject arbitrary web script or HTML via a malformed response without a status code, which is reflected ...
- EPSS 1.27%
- Veröffentlicht 02.05.2005 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
SurgeFTP 2.2m1 allows remote attackers to cause a denial of service (application hang) via the LEAK command.
- EPSS 1.11%
- Veröffentlicht 20.09.2001 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
NetWin SurgeFTP 2.0a and 1.0b allows a remote attacker to cause a denial of service (crash) via a CD command to a directory with an MS-DOS device name such as con.
- EPSS 6.2%
- Veröffentlicht 20.09.2001 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
NetWin SurgeFTP prior to 1.1h allows a remote attacker to cause a denial of service (crash) via an 'ls ..' command.