Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-5196

Опубликовано: 14 янв. 2020
Источник: nvd
CVSS3: 8.1
CVSS2: 5.5
EPSS Низкий

Описание

Cerberus FTP Server Enterprise Edition prior to versions 11.0.3 and 10.0.18 allows an authenticated attacker to create files, display hidden files, list directories, and list files without the permission to zip and download (or unzip and upload) files. There are multiple ways to bypass certain permissions by utilizing the zip and unzip features. As a result, users without permission can see files, folders, and hidden files, and can create directories without permission.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:cerberusftp:ftp_server:*:*:*:*:enterprise:*:*:*
Версия от 10.0.0 (включая) до 10.0.18 (исключая)
cpe:2.3:a:cerberusftp:ftp_server:*:*:*:*:enterprise:*:*:*
Версия от 11.0.0 (включая) до 11.0.3 (исключая)

EPSS

Процентиль: 44%
0.00216
Низкий

8.1 High

CVSS3

5.5 Medium

CVSS2

Дефекты

CWE-276

Связанные уязвимости

CVSS3: 8.1
github
больше 3 лет назад

Cerberus FTP Server Enterprise Edition prior to versions 11.0.3 and 10.0.18 allows an authenticated attacker to create files, display hidden files, list directories, and list files without the permission to zip and download (or unzip and upload) files. There are multiple ways to bypass certain permissions by utilizing the zip and unzip features. As a result, users without permission can see files, folders, and hidden files, and can create directories without permission.

EPSS

Процентиль: 44%
0.00216
Низкий

8.1 High

CVSS3

5.5 Medium

CVSS2

Дефекты

CWE-276