Progress Ws Ftp Server vulnerabilities
28 known vulnerabilities affecting progress/ws_ftp_server.
Total CVEs
28
CISA KEV
1
actively exploited
Public exploits
9
Exploited in wild
2
Severity breakdown
CRITICAL2HIGH11MEDIUM15
Vulnerabilities
Page 1 of 2
CVE-2023-40044P1HIGHCVSS 8.8KEVPoCRansomwarefixed in 8.7.4≥ 8.8, < 8.8.22023-09-27
CVE-2023-40044 [HIGH] CWE-502 CVE-2023-40044: In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a pre-authenticated attacker could leverage a .N
In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a pre-authenticated attacker could leverage a .NET deserialization vulnerability in the Ad Hoc Transfer module to execute remote commands on the underlying WS_FTP Server operating system.
nvd
CVE-2023-42657P1CRITICALCVSS 9.6Exploitedfixed in 8.7.4≥ 8.8.0, < 8.8.22023-09-27
CVE-2023-42657 [CRITICAL] CWE-22 CVE-2023-42657: In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a directory traversal vulnerability was disco
In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a directory traversal vulnerability was discovered. An attacker could leverage this vulnerability to perform file operations (delete, rename, rmdir, mkdir) on files and folders outside of their authorized WS_FTP folder path. Attackers could also escape the context of the WS_FTP Server file structure
nvd
CVE-2006-4847P3MEDIUMCVSS 6.5PoC≤ 5.05v1.0.1+19 more2006-09-19
CVE-2006-4847 [MEDIUM] CVE-2006-4847: Multiple buffer overflows in Ipswitch WS_FTP Server 5.05 before Hotfix 1 allow remote authenticated
Multiple buffer overflows in Ipswitch WS_FTP Server 5.05 before Hotfix 1 allow remote authenticated users to execute arbitrary code via long (1) XCRC, (2) XSHA1, or (3) XMD5 commands.
nvd
CVE-2008-0590P3CRITICALCVSS 9.0PoCv6.1.0.02008-02-05
CVE-2008-0590 [CRITICAL] CWE-119 CVE-2008-0590: Buffer overflow in Ipswitch WS_FTP Server with SSH 6.1.0.0 allows remote authenticated users to caus
Buffer overflow in Ipswitch WS_FTP Server with SSH 6.1.0.0 allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a long opendir command.
nvd
CVE-2003-0772P3HIGHCVSS 7.5PoCv3.42003-09-22
CVE-2003-0772 [HIGH] CVE-2003-0772: Multiple buffer overflows in WS_FTP 3 and 4 allow remote authenticated users to cause a denial of se
Multiple buffer overflows in WS_FTP 3 and 4 allow remote authenticated users to cause a denial of service and possibly execute arbitrary code via long (1) APPE (append) or (2) STAT (status) arguments.
nvd
CVE-2001-1021P3HIGHCVSS 7.5PoCv2.0.22001-07-26
CVE-2001-1021 [HIGH] CVE-2001-1021: Buffer overflows in WS_FTP 2.02 allow remote attackers to execute arbitrary code via long arguments
Buffer overflows in WS_FTP 2.02 allow remote attackers to execute arbitrary code via long arguments to (1) DELE, (2) MDTM, (3) MLST, (4) MKD, (5) RMD, (6) RNFR, (7) RNTO, (8) SIZE, (9) STAT, (10) XMKD, or (11) XRMD.
nvd
CVE-2023-42659P3HIGHCVSS 8.8fixed in 8.7.6≥ 8.8.0, < 8.8.42023-11-07
CVE-2023-42659 [HIGH] CWE-434 CVE-2023-42659: In WS_FTP Server versions prior to 8.7.6 and 8.8.4, an unrestricted file upload flaw has been ident
In WS_FTP Server versions prior to 8.7.6 and 8.8.4, an unrestricted file upload flaw has been identified. An authenticated Ad Hoc Transfer user has the ability to craft an API call which allows them to upload a file to a specified location on the underlying operating system hosting the WS_FTP Server application.
nvd
CVE-2004-1883P4HIGHCVSS 7.2PoCv4.0.22004-12-31
CVE-2004-1883 [HIGH] CVE-2004-1883: Multiple buffer overflows in Ipswitch WS_FTP Server 4.0.2 (1) allow remote authenticated users to ex
Multiple buffer overflows in Ipswitch WS_FTP Server 4.0.2 (1) allow remote authenticated users to execute arbitrary code by causing a large error string to be generated by the ALLO handler, or (2) may allow remote FTP administrators to execute arbitrary code by causing a long hostname or username to be inserted into a reply to a STAT command while a file is bei
nvd
CVE-2006-5000P3MEDIUMCVSS 6.5v5.0.22006-09-26
CVE-2006-5000 [MEDIUM] CVE-2006-5000: Multiple buffer overflows in WS_FTP Server 5.05 before Hotfix 1, and possibly other versions down to
Multiple buffer overflows in WS_FTP Server 5.05 before Hotfix 1, and possibly other versions down to 5.0, have unknown impact and remote authenticated attack vectors via the (1) XCRC, (2) XMD5, and (3) XSHA1 commands. NOTE: in the early publication of this identifier on 20060926, the description was used for the wrong issue.
nvd
CVE-2024-7745P3HIGHCVSS 8.1fixed in 8.8.82024-08-28
CVE-2024-7745 [HIGH] CWE-290 CVE-2024-7745: In WS_FTP Server versions before 8.8.8 (2022.0.8), a Missing Critical Step in Multi-Factor Authentic
In WS_FTP Server versions before 8.8.8 (2022.0.8), a Missing Critical Step in Multi-Factor Authentication of the Web Transfer Module allows users to skip the second-factor verification and log in with username and password only.
nvd
CVE-2022-27665P3MEDIUMCVSS 6.1v8.6.02023-04-03
CVE-2022-27665 [MEDIUM] CWE-79 CVE-2022-27665: Reflected XSS (via AngularJS sandbox escape expressions) exists in Progress Ipswitch WS_FTP Server 8
Reflected XSS (via AngularJS sandbox escape expressions) exists in Progress Ipswitch WS_FTP Server 8.6.0. This can lead to execution of malicious code and commands on the client due to improper handling of user-provided input. By inputting malicious payloads in the subdirectory searchbar or Add folder filename boxes, it is possible to execute client-
nvd
CVE-2024-7744P3MEDIUMCVSS 6.5fixed in 8.8.82024-08-28
CVE-2024-7744 [MEDIUM] CWE-22 CVE-2024-7744: In WS_FTP Server versions before 8.8.8 (2022.0.8), an Improper Limitation of a Pathname to a Restric
In WS_FTP Server versions before 8.8.8 (2022.0.8), an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the Web Transfer Module allows File Discovery, Probe System Files, User-Controlled Filename, Path Traversal.
An authenticated file download flaw has been identified where a user can craft an API call th
nvd
CVE-2023-40046P3HIGHCVSS 7.2fixed in 8.7.4≥ 8.8, < 8.8.22023-09-27
CVE-2023-40046 [HIGH] CWE-89 CVE-2023-40046: In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a SQL injection vulnerability exists in the
In WS_FTP Server versions prior to 8.7.4 and 8.8.2,
a SQL injection vulnerability exists in the WS_FTP Server manager interface. An attacker may be able to infer information about the structure and contents of the database and execute SQL statements that alter or delete database elements.
nvd
CVE-2023-24029P3HIGHCVSS 7.2fixed in 8.82023-02-03
CVE-2023-24029 [HIGH] CWE-863 CVE-2023-24029: In Progress WS_FTP Server before 8.8, it is possible for a host administrator to elevate their privi
In Progress WS_FTP Server before 8.8, it is possible for a host administrator to elevate their privileges via the administrative interface due to insufficient authorization controls applied on user modification workflows.
nvd
CVE-2004-1884P3HIGHCVSS 7.5v1.0.1v1.0.2+16 more2004-03-23
CVE-2004-1884 [HIGH] CVE-2004-1884: Ipswitch WS_FTP Server 4.0.2 has a backdoor XXSESS_MGRYY username with a default password, which all
Ipswitch WS_FTP Server 4.0.2 has a backdoor XXSESS_MGRYY username with a default password, which allows remote attackers to gain access.
nvd
CVE-1999-1171P4MEDIUMCVSS 4.6PoCv1.0.1.ev1.0.2.e1999-02-02
CVE-1999-1171 [MEDIUM] CVE-1999-1171: IPswitch WS_FTP allows local users to gain additional privileges and modify or add mail accounts by
IPswitch WS_FTP allows local users to gain additional privileges and modify or add mail accounts by setting the "flags" registry key to 1920.
nvd
CVE-2004-1643P4MEDIUMCVSS 5.0PoCv5.0.22004-08-29
CVE-2004-1643 [MEDIUM] CVE-2004-1643: WS_FTP 5.0.2 allows remote authenticated users to cause a denial of service (CPU consumption) via a
WS_FTP 5.0.2 allows remote authenticated users to cause a denial of service (CPU consumption) via a CD command that contains an invalid path with a "../" sequence.
nvd
CVE-1999-1170P4MEDIUMCVSS 4.6PoCv1.0.1.ev1.0.2.e1999-01-02
CVE-1999-1170 [MEDIUM] CVE-1999-1170: IPswitch IMail allows local users to gain additional privileges and modify or add mail accounts by s
IPswitch IMail allows local users to gain additional privileges and modify or add mail accounts by setting the "flags" registry key to 1920.
nvd
CVE-2002-0826P4HIGHCVSS 7.5v3.1.12002-08-12
CVE-2002-0826 [HIGH] CVE-2002-0826: Buffer overflow in WS_FTP FTP Server 3.1.1 allows remote authenticated users to execute arbitrary co
Buffer overflow in WS_FTP FTP Server 3.1.1 allows remote authenticated users to execute arbitrary code via a long SITE CPWD command.
nvd
CVE-2006-5001P4MEDIUMCVSS 5.0≤ 5.05v5.0.22006-09-26
CVE-2006-5001 [MEDIUM] CVE-2006-5001: Unspecified vulnerability in the log analyzer in WS_FTP Server 5.05 before Hotfix 1, and possibly ot
Unspecified vulnerability in the log analyzer in WS_FTP Server 5.05 before Hotfix 1, and possibly other versions down to 5.0, prevents certain sensitive information from being displayed in the (1) Files and (2) Summary tabs. NOTE: in the early publication of this identifier on 20060926, the description was used for the wrong issue.
nvd
1 / 2Next →