Surgeftp

Netwin · 13 CVEs

CVE-2012-10028
HIGH

Netwin SurgeFTP <= v23c8 Authenticated RCE

Aug 5, 2025

CVE-2017-17933
MEDIUM

cgi/surgeftpmgr.cgi (aka the Web Manager interface on TCP port 7021 or 9021) in NetWin SurgeFTP version 23f2 has XSS vi…

Dec 29, 2017

CVE-2013-4742
HIGH

Buffer overflow in NetWin SurgeFTP before 23d2 allows remote attackers to cause a denial of service (crash) or possibly…

Aug 9, 2013

CVE-2010-1068
MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in surgeftpmgr.cgi in NetWin SurgeFTP 2.3a6 allow remote attackers…

Mar 23, 2010

CVE-2008-1052
MEDIUM

The administration web interface in NetWin SurgeFTP 2.3a2 and earlier allows remote attackers to cause a denial of serv…

Feb 27, 2008

CVE-2007-3769
MEDIUM

Cross-site scripting (XSS) vulnerability in the mirrored server management interface in SurgeFTP 2.3a1 allows user-assi…

Jul 15, 2007

CVE-2007-3768
HIGH

The mirror mechanism in SurgeFTP 2.3a1 allows user-assisted, remote FTP servers to cause a denial of service (restart)…

Jul 15, 2007

CVE-2005-1034
MEDIUM

SurgeFTP 2.2m1 allows remote attackers to cause a denial of service (application hang) via the LEAK command.

Apr 9, 2005

CVE-2001-1356
HIGH

NetWin SurgeFTP 2.0f and earlier encrypts passwords using weak hashing, a fixed salt value and modulo 40 calculations,…

Jun 11, 2002

CVE-2001-1355
HIGH

Buffer overflows in NetWin Authentication Module (NWAuth) 3.0b and earlier, as implemented in DMail, SurgeFTP, and poss…

Jun 11, 2002

CVE-2001-1354
MEDIUM

NetWin Authentication module (NWAuth) 2.0 and 3.0b, as implemented in SurgeFTP, DMail, and possibly other packages, use…

Jun 11, 2002

CVE-2001-0698
MEDIUM

Directory traversal vulnerability in NetWin SurgeFTP 2.0a and 1.0b allows a remote attacker to list arbitrary files and…

Mar 9, 2002

CVE-2001-0697
MEDIUM

NetWin SurgeFTP prior to 1.1h allows a remote attacker to cause a denial of service (crash) via an 'ls ..' command.

Mar 9, 2002

CVE-2001-0696
MEDIUM

NetWin SurgeFTP 2.0a and 1.0b allows a remote attacker to cause a denial of service (crash) via a CD command to a direc…

Mar 9, 2002

Showing 1 to 13 of 13 CVEs