Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface in Cerberus FTP Server before 5.0.5.0 allow remote attackers to hijack the authentication of administrators for requests that (1) add a user account or (2) reconfigure the state of the FTP service, as demonstrated by a request to usermanager/users/modify.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Cerberus FTP Server 多个跨站请求伪造漏洞
Vulnerability Description
Cerberus FTP Server是美国Cerberus公司的一款免费、多线程并运行在Windows操作系统中的FTP服务器。 Cerberus FTP Server 5.0.5.0之前版本中的web接口中存在多个跨站请求伪造(CSRF)漏洞。远程攻击者可利用这些漏洞劫持管理员身份验证(1)添加用户账户或(2)重新配置FTP服务状态的请求。如请求到usermanager/users/modify。
CVSS Information
N/A
Vulnerability Type
N/A