Описание
Monsta FTP versions 2.11 and earlier contain a vulnerability that allows unauthenticated arbitrary file uploads. This flaw enables attackers to execute arbitrary code by uploading a specially crafted file from a malicious (S)FTP server.
Ссылки
- ExploitThird Party Advisory
- Release Notes
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.11 (включая)
cpe:2.3:a:monstaftp:monsta_ftp:*:*:*:*:*:*:*:*
EPSS
Процентиль: 98%
0.60331
Средний
9.8 Critical
CVSS3
Дефекты
CWE-434
Связанные уязвимости
github
3 месяца назад
Monsta FTP versions 2.11 and earlier contain a vulnerability that allows unauthenticated arbitrary file uploads. This flaw enables attackers to execute arbitrary code by uploading a specially crafted file from a malicious (S)FTP server.
EPSS
Процентиль: 98%
0.60331
Средний
9.8 Critical
CVSS3
Дефекты
CWE-434