Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6mm6-4c6x-2xpr

Опубликовано: 27 сент. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 8.3

Описание

In WS_FTP Server version 8.7.0 prior to 8.7.4 and

version 8.8.0 prior to 8.8.2, a reflected cross-site scripting (XSS) vulnerability exists in WS_FTP Server's Ad Hoc Transfer module.  An attacker could leverage this vulnerability to target WS_FTP Server users with a specialized payload which results in the execution of malicious JavaScript within the context of the victims browser.

In WS_FTP Server version 8.7.0 prior to 8.7.4 and

version 8.8.0 prior to 8.8.2, a reflected cross-site scripting (XSS) vulnerability exists in WS_FTP Server's Ad Hoc Transfer module.  An attacker could leverage this vulnerability to target WS_FTP Server users with a specialized payload which results in the execution of malicious JavaScript within the context of the victims browser.

EPSS

Процентиль: 11%
0.00037
Низкий

8.3 High

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 8.3
nvd
больше 2 лет назад

In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a reflected cross-site scripting (XSS) vulnerability exists in WS_FTP Server's Ad Hoc Transfer module.  An attacker could leverage this vulnerability to target WS_FTP Server users with a specialized payload which results in the execution of malicious JavaScript within the context of the victims browser.

CVSS3: 8.3
fstec
больше 2 лет назад

Уязвимость модуля Ad Hoc Transfer сервера WS_FTP Server, позволяющая нарушителю проводить межсайтовые сценарные атаки

EPSS

Процентиль: 11%
0.00037
Низкий

8.3 High

CVSS3

Дефекты

CWE-79