Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2020-27735 PoC — Wing FTP 跨站脚本漏洞

Source
Associated Vulnerability
Title:Wing FTP 跨站脚本漏洞 (CVE-2020-27735)
Description:Wing FTP Server是一套跨平台的FTP服务器软件。 Wing FTP 6.4.4 存在跨站脚本漏洞,攻击者可利用该漏洞在用户的浏览器中执行任意HTML和JavaScript。
Description
Wing FTP 6.4.4 is vulnerable to cross-site scripting via its web interface because an arbitrary IFRAME element can be included in the help pages via a crafted link, leading to the execution of (sandboxed) arbitrary HTML and JavaScript in the user's browser.
File Snapshot

id: CVE-2020-27735 info: name: Wing FTP 6.4.4 - Cross-Site Scripting author: pikpikcu severit ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.