South River Technologies TitanFTP NextGen(South River Technologies Titan FTP NextGen)是美国South River Technologies公司的一款本机支持集群以实现高可用性和故障转移的 SFTP/FTP 服务器。 South River Technologies TitanFTP NextGen 1.94.1205版本及之前版本存在安全漏洞,该漏洞源于move-file函数的 newPath 参数中存在路径遍历漏洞。攻
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | TitanFTP versions up to 1.94.1205 contain a path traversal vulnerability in the move-file function where the newPath parameter is improperly validated. An authenticated user can upload a file and then move it to any location on the server filesystem, potentially allowing arbitrary file placement and system compromise. | https://github.com/projectdiscovery/nuclei-templates/blob/main/network/cves/2023/CVE-2023-22629.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2023-0830 | 6.3 MEDIUM | EasyNAS backup.pl system os command injection |
| CVE-2021-46023 | mruby 缓冲区错误漏洞 | |
| CVE-2022-29557 | LexisNexis Firco Compliance Link 跨站请求伪造漏洞 | |
| CVE-2023-24159 | TOTOLINK CA300-PoE 命令注入漏洞 | |
| CVE-2023-24160 | TOTOLINK CA300-PoE 命令注入漏洞 | |
| CVE-2023-24161 | TOTOLINK CA300-PoE 命令注入漏洞 | |
| CVE-2023-24187 | ureport v2.2.9 代码问题漏洞 | |
| CVE-2023-25725 | HAProxy 安全漏洞 | |
| CVE-2023-25758 | Onekey Touch devices 安全漏洞 |
No comments yet