Описание
Monsta FTP 2.10.1 or below allows external control of paths used in filesystem operations. This allows attackers to read and write arbitrary local files, allowing an attacker to gain remote code execution in common deployments.
Ссылки
- Third Party Advisory
- Release NotesVendor Advisory
- Third Party Advisory
- Release NotesVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.10.1 (включая)
cpe:2.3:a:monstaftp:monsta_ftp:*:*:*:*:*:*:*:*
EPSS
Процентиль: 86%
0.03074
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-610
Связанные уязвимости
github
больше 3 лет назад
Monsta FTP 2.10.1 or below allows external control of paths used in filesystem operations. This allows attackers to read and write arbitrary local files, allowing an attacker to gain remote code execution in common deployments.
EPSS
Процентиль: 86%
0.03074
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-610