← Retour aux CVEs
CVE-2020-8634
HIGH7.8
Description
Wing FTP Server v6.2.3 for Linux, macOS, and Solaris sets insecure permissions on files modified within the HTTP file management interface, resulting in files being saved with world-readable and world-writable permissions. If a sensitive system file were edited this way, a low-privilege user may escalate privileges to root.
Details CVE
Score CVSS v3.17.8
SeveriteHIGH
Vecteur CVSSCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vecteur d'attaqueLOCAL
ComplexiteLOW
Privileges requisLOW
Interaction utilisateurNONE
Publie3/7/2020
Derniere modification11/21/2024
Sourcenvd
Observations honeypot0
Produits affectes
wftpserver:wing_ftp_server
Faiblesses (CWE)
CWE-281
References
https://www.hooperlabs.xyz/disclosures/cve-2020-8635.php(cve@mitre.org)
https://www.hooperlabs.xyz/disclosures/cve-2020-8635.php(af854a3a-2127-422b-91ae-364da2661108)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.