Vulnerabilities > Netwin > Surgeftp > 2.3a6

DATE CVE VULNERABILITY TITLE RISK
2013-08-09 CVE-2013-4742 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Netwin Surgeftp
Buffer overflow in NetWin SurgeFTP before 23d2 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long string within the authentication request.
network
low complexity
netwin CWE-119
7.5
2010-03-23 CVE-2010-1068 Cross-Site Scripting vulnerability in Netwin Surgeftp 2.3A6
Multiple cross-site scripting (XSS) vulnerabilities in surgeftpmgr.cgi in NetWin SurgeFTP 2.3a6 allow remote attackers to inject arbitrary web script or HTML via the (1) domainid or (2) classid parameter in a class action.
network
netwin CWE-79
4.3