Vulnerabilities > CVE-2020-8634 - Improper Preservation of Permissions vulnerability in Wftpserver Wing FTP Server 6.2.3
Attack vector
LOCAL Attack complexity
LOW Privileges required
NONE Confidentiality impact
COMPLETE Integrity impact
COMPLETE Availability impact
COMPLETE Summary
Wing FTP Server v6.2.3 for Linux, macOS, and Solaris sets insecure permissions on files modified within the HTTP file management interface, resulting in files being saved with world-readable and world-writable permissions. If a sensitive system file were edited this way, a low-privilege user may escalate privileges to root.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 3 |
Common Weakness Enumeration (CWE)
Packetstorm
data source | https://packetstormsecurity.com/files/download/156591/wingftpserver623-escalate.txt |
id | PACKETSTORM:156591 |
last seen | 2020-03-02 |
published | 2020-03-02 |
reporter | Cary Hooper |
source | https://packetstormsecurity.com/files/156591/Wing-FTP-Server-6.2.3-Privilege-Escalation.html |
title | Wing FTP Server 6.2.3 Privilege Escalation |