Описание
Netwin SurgeFTP version 23c8 and prior contains a vulnerability in its web-based administrative console that allows authenticated users to execute arbitrary system commands via crafted POST requests to surgeftpmgr.cgi. This can lead to full remote code execution on the underlying system.
Ссылки
EPSS
Процентиль: 98%
0.53689
Средний
Дефекты
CWE-78
Связанные уязвимости
github
6 месяцев назад
Netwin SurgeFTP version 23c8 and prior contains a vulnerability in its web-based administrative console that allows authenticated users to execute arbitrary system commands via crafted POST requests to `surgeftpmgr.cgi`. This can lead to full remote code execution on the underlying system.
EPSS
Процентиль: 98%
0.53689
Средний
Дефекты
CWE-78