← Retour aux CVEs
CVE-2023-40046
HIGH8.2
Description
In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a SQL injection vulnerability exists in the WS_FTP Server manager interface. An attacker may be able to infer information about the structure and contents of the database and execute SQL statements that alter or delete database elements.
Details CVE
Score CVSS v3.18.2
SeveriteHIGH
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:L
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisHIGH
Interaction utilisateurNONE
Publie9/27/2023
Derniere modification11/21/2024
Sourcenvd
Observations honeypot0
Produits affectes
progress:ws_ftp_server
Faiblesses (CWE)
CWE-89CWE-89
References
https://community.progress.com/s/article/WS-FTP-Server-Critical-Vulnerability-September-2023(security@progress.com)
https://www.progress.com/ws_ftp(security@progress.com)
https://community.progress.com/s/article/WS-FTP-Server-Critical-Vulnerability-September-2023(af854a3a-2127-422b-91ae-364da2661108)
https://www.progress.com/ws_ftp(af854a3a-2127-422b-91ae-364da2661108)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.