Search Results (22 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2020-8634 1 Wftpserver 1 Wing Ftp Server 2024-11-21 7.8 High
Wing FTP Server v6.2.3 for Linux, macOS, and Solaris sets insecure permissions on files modified within the HTTP file management interface, resulting in files being saved with world-readable and world-writable permissions. If a sensitive system file were edited this way, a low-privilege user may escalate privileges to root.
CVE-2020-27735 1 Wftpserver 1 Wing Ftp Server 2024-11-21 6.1 Medium
An XSS issue was discovered in Wing FTP 6.4.4. An arbitrary IFRAME element can be included in the help pages via a crafted link, leading to the execution of (sandboxed) arbitrary HTML and JavaScript in the user's browser.