MEDIUM
Cross-site scripting (XSS) vulnerability in admin_loginok.html in the Administrator web interface in Wing FTP Server for Windows 3.5.0 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted POST request
Published Jun 23, 2010
4.3
MEDIUMCVSS 2.0
EPSS 1.99%
Description
Cross-site scripting (XSS) vulnerability in admin_loginok.html in the Administrator web interface in Wing FTP Server for Windows 3.5.0 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted POST request.
Affected products
No data.
AND
OR
- ≤ 3.5.0
- 1.1
- 1.2
- 1.3
- 1.4
- 1.5
- 1.6
- 2.0
- 2.1
- 2.3
- 2.4
- 3.0.0
- 3.1.0
- 3.1.2
- 3.2.0
- 3.2.4
- 3.2.8
- 3.3.0
- 3.3.4
- 3.3.5
- 3.4.0
- 3.4.1
- 3.4.2
- 3.4.3
- 3.4.5
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (7)
- http://archives.neohapsis.com/archives/bugtraq/2010-06/0031.html mailing-listx_refsource_BUGTRAQExploit
- http://labs-werew01f.sectester.net/2010/06/wing-ftp-server-cross-site-scripting.html x_refsource_MISCExploit
- http://seclists.org/fulldisclosure/2010/Jun/128 mailing-listx_refsource_FULLDISCExploit
- http://seclists.org/fulldisclosure/2010/Jun/49 mailing-listx_refsource_FULLDISCExploit
- http://www.osvdb.org/65444 vdb-entryx_refsource_OSVDB
- http://www.securityfocus.com/bid/40510 vdb-entryx_refsource_BID
- https://exchange.xforce.ibmcloud.com/vulnerabilities/59094 vdb-entryx_refsource_XF
| Link | Providers | Tags |
|---|---|---|
| http://archives.neohapsis.com/archives/bugtraq/2010-06/0031.html | mailing-listx_refsource_BUGTRAQExploit | |
| http://labs-werew01f.sectester.net/2010/06/wing-ftp-server-cross-site-scripting.html | x_refsource_MISCExploit | |
| http://seclists.org/fulldisclosure/2010/Jun/128 | mailing-listx_refsource_FULLDISCExploit | |
| http://seclists.org/fulldisclosure/2010/Jun/49 | mailing-listx_refsource_FULLDISCExploit | |
| http://www.osvdb.org/65444 | vdb-entryx_refsource_OSVDB | |
| http://www.securityfocus.com/bid/40510 | vdb-entryx_refsource_BID | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/59094 | vdb-entryx_refsource_XF |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 23, 2010
Updated Aug 7, 2024
Reserved Jun 22, 2010
Link CVE-2010-2428
CISA Vulnrichment
Updated n/a