Provide Ftp Server
Provideserver · 8 CVEs
An issue was discovered in ProVide (formerly zFTPServer) through 13.1. CSRF exists in the User Web Interface, as demons…
Apr 12, 2020
An issue was discovered in ProVide (formerly zFTPServer) through 13.1. The User Web Interface has Multiple Stored and R…
Apr 12, 2020
An issue was discovered in ProVide (formerly zFTPServer) through 13.1. /ajax/GetInheritedProperties allows HTTP Respons…
Apr 12, 2020
An issue was discovered in ProVide (formerly zFTPServer) through 13.1. The Admin Web Interface has Multiple Stored and…
Apr 12, 2020
An issue was discovered in ProVide (formerly zFTPServer) through 13.1. /ajax/ImportCertificate allows an attacker to lo…
Apr 12, 2020
An issue was discovered in ProVide (formerly zFTPServer) through 13.1. The Admin Interface allows CSRF for actions such…
Apr 12, 2020
An issue was discovered in ProVide (formerly zFTPServer) through 13.1. It doesn't enforce permission over Windows Symli…
Apr 12, 2020
An issue was discovered in ProVide (formerly zFTPServer) through 13.1. Privilege escalation can occur via the /ajax/Set…
Apr 12, 2020
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2020-11701 | An issue was discovered in ProVide (formerly zFTPServer) through 13.1. CSRF exists in the User Web Interface, as demonstrated by granting filesystem access to… | HIGH | 0.50% | Apr 12, 2020 |
| CVE-2020-11702 | An issue was discovered in ProVide (formerly zFTPServer) through 13.1. The User Web Interface has Multiple Stored and Reflected XSS issues. Collaborate is Refl… | MEDIUM | 0.68% | Apr 12, 2020 |
| CVE-2020-11703 | An issue was discovered in ProVide (formerly zFTPServer) through 13.1. /ajax/GetInheritedProperties allows HTTP Response Splitting via the language parameter. | HIGH | 0.93% | Apr 12, 2020 |
| CVE-2020-11704 | An issue was discovered in ProVide (formerly zFTPServer) through 13.1. The Admin Web Interface has Multiple Stored and Reflected XSS. GetInheritedProperties is… | MEDIUM | 0.68% | Apr 12, 2020 |
| CVE-2020-11705 | An issue was discovered in ProVide (formerly zFTPServer) through 13.1. /ajax/ImportCertificate allows an attacker to load an arbitrary certificate in .pfx form… | CRITICAL | 0.91% | Apr 12, 2020 |
| CVE-2020-11706 | An issue was discovered in ProVide (formerly zFTPServer) through 13.1. The Admin Interface allows CSRF for actions such as: Change any username and password, a… | HIGH | 0.50% | Apr 12, 2020 |
| CVE-2020-11707 | An issue was discovered in ProVide (formerly zFTPServer) through 13.1. It doesn't enforce permission over Windows Symlinks or Junctions. As a result, a low-pri… | HIGH | 1.00% | Apr 12, 2020 |
| CVE-2020-11708 | An issue was discovered in ProVide (formerly zFTPServer) through 13.1. Privilege escalation can occur via the /ajax/SetUserInfo messages parameter because of t… | CRITICAL | 1.60% | Apr 12, 2020 |
Showing 1 to 8 of 8 CVEs