Wftpserver

Wing Ftp Server

16 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Warnung Medienbericht Exploit
  • EPSS 92.4%
  • Veröffentlicht 10.07.2025 00:00:00
  • Zuletzt bearbeitet 05.11.2025 19:26:31

In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection of arbitrary Lua code into user session files. This can be used to execute arbitrary system commands with the privileges of the FTP...

Exploit
  • EPSS 0.05%
  • Veröffentlicht 10.07.2025 00:00:00
  • Zuletzt bearbeitet 17.07.2025 13:18:45

In Wing FTP Server through 7.4.4, the administrative web interface (listening by default on port 5466) runs as root or SYSTEM by default. The web application itself offers several legitimate ways to execute arbitrary system commands (i.e., through th...

Exploit
  • EPSS 0.48%
  • Veröffentlicht 10.07.2025 00:00:00
  • Zuletzt bearbeitet 17.07.2025 13:17:06

loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a long value in the UID cookie.

Exploit
  • EPSS 0.03%
  • Veröffentlicht 10.07.2025 00:00:00
  • Zuletzt bearbeitet 17.07.2025 13:31:12

Wing FTP Server before 7.4.4 does not properly validate and sanitize the url parameter of the downloadpass.html endpoint, allowing injection of an arbitrary link. If a user clicks a crafted link, this discloses a cleartext password to the attacker.

Exploit
  • EPSS 0.31%
  • Veröffentlicht 26.05.2025 13:31:05
  • Zuletzt bearbeitet 02.07.2025 17:42:07

A vulnerability has been found in Wing FTP Server up to 7.4.3 and classified as critical. Affected by this vulnerability is an unknown functionality of the component Lua Admin Console. The manipulation leads to execution with unnecessary privileges. ...

  • EPSS 0.1%
  • Veröffentlicht 12.09.2023 09:15:08
  • Zuletzt bearbeitet 21.11.2024 08:12:23

Insecure default permissions in Wing FTP Server (Admin Web Client) allows for privilege escalation.This issue affects Wing FTP Server: <= 7.2.0.

  • EPSS 0.25%
  • Veröffentlicht 12.09.2023 09:15:08
  • Zuletzt bearbeitet 21.11.2024 08:12:23

Insecure storage of sensitive information in Wing FTP Server (User Web Client) allows information elicitation.This issue affects Wing FTP Server: <= 7.2.0.

  • EPSS 0.15%
  • Veröffentlicht 12.09.2023 09:15:08
  • Zuletzt bearbeitet 21.11.2024 08:12:23

Weak access control in Wing FTP Server (Admin Web Client) allows for privilege escalation.This issue affects Wing FTP Server: <= 7.2.0.

  • EPSS 0.13%
  • Veröffentlicht 12.09.2023 09:15:07
  • Zuletzt bearbeitet 21.11.2024 08:12:22

Improper encoding or escaping of output in Wing FTP Server (User Web Client) allows Cross-Site Scripting (XSS).This issue affects Wing FTP Server: <= 7.2.0.

Exploit
  • EPSS 37%
  • Veröffentlicht 26.01.2021 18:15:46
  • Zuletzt bearbeitet 21.11.2024 05:21:43

An XSS issue was discovered in Wing FTP 6.4.4. An arbitrary IFRAME element can be included in the help pages via a crafted link, leading to the execution of (sandboxed) arbitrary HTML and JavaScript in the user's browser.