Progress Software WS_FTP Server是美国Progress Software公司的一个有效的、高度可管理的 FTP 服务器。 WS_FTP Server 8.7.4之前版本、8.8.2版本存在SQL注入漏洞。攻击者利用该漏洞能够推断有关数据库的结构和内容的信息,并执行更改或删除数据库元素的SQL语句。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Progress Software Corporation | WS_FTP Server | 8.8.0 ~ 8.8.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-40044 | 10.0 CRITICAL | WS_FTP Server Ad Hoc Transfer Module .NET Deserialization Vulnerability |
| CVE-2023-42657 | 9.9 CRITICAL | WS_FTP Server Directory Traversal |
| CVE-2023-40047 | 8.3 HIGH | WS_FTP Server Stored Cross-Site Scripting Vulnerability |
| CVE-2023-40045 | 8.3 HIGH | WS_FTP Server Ad Hoc Transfer Module Reflected Cross-Site Scripting Vulnerability |
| CVE-2023-40048 | 6.8 MEDIUM | WS_FTP Server Cross-Site Request Forgery (CSRF) Vulnerability |
| CVE-2023-40049 | 5.3 MEDIUM | WS_FTP Server Information Disclosure via Directory Listing |
No comments yet