Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5wrh-xjpw-88r6

Опубликовано: 14 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.6
CVSS3: 8.8

Описание

Wing FTP Server versions 4.3.8 and below contain an authenticated remote code execution vulnerability that allows attackers to execute arbitrary PowerShell commands through the admin interface. Attackers can leverage a crafted Lua script payload with base64-encoded PowerShell to establish a reverse TCP shell by authenticating and sending a malicious request to the admin panel.

Wing FTP Server versions 4.3.8 and below contain an authenticated remote code execution vulnerability that allows attackers to execute arbitrary PowerShell commands through the admin interface. Attackers can leverage a crafted Lua script payload with base64-encoded PowerShell to establish a reverse TCP shell by authenticating and sending a malicious request to the admin panel.

8.6 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-94

Связанные уязвимости

nvd
25 дней назад

Rejected reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue.

8.6 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-94