Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2020-5195

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Cerberus FTP Server 11.0.1之前版本和10.0.17之前版本中的IMG元素存在跨站脚本漏洞。该漏洞源于WEB应用缺少对客户端数据的正确验证。攻击者可利用该漏洞执行客户端代码。

AI Predicted 6.1 Difficulty: Moderate EPSS 1.22% · P66
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2020-5195

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
Reflected XSS through an IMG element in Cerberus FTP Server prior to versions 11.0.1 and 10.0.17 allows a remote attacker to execute arbitrary JavaScript or HTML via a crafted public folder URL. This occurs because of the folder_up.png IMG element not properly sanitizing user-inserted directory paths. The path modification must be done on a publicly shared folder for a remote attacker to insert arbitrary JavaScript or HTML. The vulnerability impacts anyone who clicks the malicious link crafted by the attacker.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Cerberus FTP Server 跨站脚本漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Cerberus FTP Server 11.0.1之前版本和10.0.17之前版本中的IMG元素存在跨站脚本漏洞。该漏洞源于WEB应用缺少对客户端数据的正确验证。攻击者可利用该漏洞执行客户端代码。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2020-5195

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2020-5195

登录查看更多情报信息。

Other References for CVE-2020-5195 (3)

Same Patch Batch · n/a · 2020-01-13 · 41 CVEs total

CVE-2014-9382 Freebox OS Web interface 跨站请求伪造漏洞
CVE-2020-5390 PySAML2 数据伪造问题漏洞
CVE-2019-20212 WordPress CTHthemes CityBook、TownHub和EasyBook 跨站脚本漏洞
CVE-2019-19891 Mitel SIP-DECT 安全漏洞
CVE-2019-20211 WordPress CTHthemes CityBook、TownHub和EasyBook 跨站脚本漏洞
CVE-2019-20210 WordPress CTHthemes CityBook、TownHub和EasyBook 跨站脚本漏洞
CVE-2019-20209 WordPress CTHthemes CityBook、TownHub和EasyBook 跨站脚本漏洞
CVE-2020-6859 WordPress Ultimate Member 安全漏洞
CVE-2019-18894 Avast Premium Security 操作系统命令注入漏洞
CVE-2019-18893 Avast Secure Browser和AVG Secure Browser Video Downloader组件跨站脚本漏洞
CVE-2019-19728 SchedMD Slurm 安全漏洞
CVE-2013-6225 LiveZilla 路径遍历漏洞
CVE-2014-5381 Grand MA 300 安全漏洞
CVE-2014-5380 Grand MA 300 安全漏洞
CVE-2014-6039 ZOHO ManageEngine EventLog Analyzer 安全漏洞
CVE-2014-6038 ZOHO ManageEngine EventLog Analyzer 信息泄露漏洞
CVE-2014-6059 WordPress Advanced Access Manager 安全漏洞
CVE-2020-6860 libmysofa 缓冲区错误漏洞
CVE-2020-6851 OpenJPEG 缓冲区错误漏洞
CVE-2020-6848 Axper 跨站脚本漏洞

Showing top 20 of 41 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2020-5195

No comments yet


Leave a comment