Progress / WS Ftp Server
29 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2024-9999 | Multi-Factor Authentication Bypass in Progress WS_FTP Server | MEDIUM | 6.5 | Nov 12, 2024 |
| CVE-2024-7745 | Multi-Factor Authentication Bypass in Progress WS_FTP Server | HIGH | 8.1 | Aug 28, 2024 |
| CVE-2024-7744 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Progress WS_FTP Server | MEDIUM | 6.5 | Aug 28, 2024 |
| CVE-2024-1474 | WS_FTP Server Reflected Cross-Site Scripting in Administrative Interface | HIGH | 7.5 | Feb 21, 2024 |
| CVE-2023-42659 | WS_FTP Server Arbitrary File Upload | CRITICAL | 9.1 | Nov 7, 2023 |
| CVE-2023-40049 | WS_FTP Server Information Disclosure via Directory Listing | MEDIUM | 5.3 | Sep 27, 2023 |
| CVE-2023-40048 | WS_FTP Server Cross-Site Request Forgery (CSRF) Vulnerability | MEDIUM | 6.8 | Sep 27, 2023 |
| CVE-2023-40047 | WS_FTP Server Stored Cross-Site Scripting Vulnerability | HIGH | 8.3 | Sep 27, 2023 |
| CVE-2023-40046 | WS_FTP Server SQL Injection via Administrative Interface | HIGH | 8.2 | Sep 27, 2023 |
| CVE-2023-40045 | WS_FTP Server Ad Hoc Transfer Module Reflected Cross-Site Scripting Vulnerability | HIGH | 8.3 | Sep 27, 2023 |
| CVE-2023-42657 | WS_FTP Server Directory Traversal | CRITICAL | 9.9 | Sep 27, 2023 |
| CVE-2023-40044 KEV | WS_FTP Server Ad Hoc Transfer Module .NET Deserialization Vulnerability | CRITICAL | 10.0 | Sep 27, 2023 |
| CVE-2022-27665 | Reflected XSS (via AngularJS sandbox escape expressions) exists in Progress Ipswitch WS_FTP Server 8.6.0. This can lead to execution of malicious code and comm… | MEDIUM | 6.1 | Apr 3, 2023 |
| CVE-2023-24029 | In Progress WS_FTP Server before 8.8, it is possible for a host administrator to elevate their privileges via the administrative interface due to insufficient… | HIGH | 7.2 | Feb 3, 2023 |
| CVE-2019-12143 | A Directory Traversal issue was discovered in SSHServerAPI.dll in Progress ipswitch WS_FTP Server 2018 before 8.6.1. An attacker can supply a string using spec… | MEDIUM | 5.3 | Jun 11, 2019 |
| CVE-2008-0590 | Buffer overflow in Ipswitch WS_FTP Server with SSH 6.1.0.0 allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrar… | HIGH | 9.0 | Feb 5, 2008 |
| CVE-2006-5001 | Unspecified vulnerability in the log analyzer in WS_FTP Server 5.05 before Hotfix 1, and possibly other versions down to 5.0, prevents certain sensitive inform… | MEDIUM | 5.0 | Sep 26, 2006 |
| CVE-2006-5000 | Multiple buffer overflows in WS_FTP Server 5.05 before Hotfix 1, and possibly other versions down to 5.0, have unknown impact and remote authenticated attack v… | MEDIUM | 6.5 | Sep 26, 2006 |
| CVE-2006-4847 | Multiple buffer overflows in Ipswitch WS_FTP Server 5.05 before Hotfix 1 allow remote authenticated users to execute arbitrary code via long (1) XCRC, (2) XSHA… | MEDIUM | 6.5 | Sep 19, 2006 |
| CVE-2004-1885 | Ipswitch WS_FTP Server 4.0.2 allows remote authenticated users to execute arbitrary programs as SYSTEM by using the SITE command to modify certain iFtpSvc opti… | HIGH | 7.2 | May 10, 2005 |
| CVE-2004-1884 | Ipswitch WS_FTP Server 4.0.2 has a backdoor XXSESS_MGRYY username with a default password, which allows remote attackers to gain access. | HIGH | 7.5 | May 10, 2005 |
| CVE-2004-1883 | Multiple buffer overflows in Ipswitch WS_FTP Server 4.0.2 (1) allow remote authenticated users to execute arbitrary code by causing a large error string to be… | HIGH | 7.2 | May 10, 2005 |
| CVE-2004-1848 | Ipswitch WS_FTP Server 4.0.2 allows remote attackers to cause a denial of service (disk consumption) and bypass file size restrictions via a REST command with… | MEDIUM | 5.0 | May 10, 2005 |
| CVE-2004-1643 | WS_FTP 5.0.2 allows remote authenticated users to cause a denial of service (CPU consumption) via a CD command that contains an invalid path with a "../" seque… | MEDIUM | 5.0 | Feb 20, 2005 |
| CVE-2003-0772 | Multiple buffer overflows in WS_FTP 3 and 4 allow remote authenticated users to cause a denial of service and possibly execute arbitrary code via long (1) APPE… | HIGH | 7.5 | Sep 12, 2003 |
Showing 1 to 25 of 29 CVEs