Vulnerabilities > Wftpserver

DATE CVE VULNERABILITY TITLE RISK
2010-06-24 CVE-2010-2428 Cross-Site Scripting vulnerability in Wftpserver Wing FTP Server
Cross-site scripting (XSS) vulnerability in admin_loginok.html in the Administrator web interface in Wing FTP Server for Windows 3.5.0 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted POST request.
4.3
2009-01-29 CVE-2009-0351 Buffer Errors vulnerability in Wftpserver Winftp FTP Server 2.3.0
Stack-based buffer overflow in WFTPSRV.exe in WinFTP 2.3.0 allows remote authenticated users to execute arbitrary code via a long LIST argument beginning with an * (asterisk) character.
network
low complexity
wftpserver CWE-119
critical
9.0
2008-12-19 CVE-2008-5666 Resource Management Errors vulnerability in Wftpserver Winftp FTP Server 2.3.0
WinFTP FTP Server 2.3.0, when passive (aka PASV) mode is used, allows remote authenticated users to cause a denial of service via a sequence of FTP sessions that include an invalid "NLST -1" command.
3.5