VYPR

Ws FTP

by Ipswitch, Inc.

CVEs (15)

  • CVE-2017-16513HigNov 3, 2017
    risk 0.54cvss 7.8epss 0.02

    Ipswitch WS_FTP Professional before 12.6.0.3 has buffer overflows in the local search field and the backup locations field, aka WSCLT-1729.

  • CVE-2008-5692Dec 19, 2008
    risk 0.04cvss epss 0.08

    Ipswitch WS_FTP Server Manager before 6.1.1, and possibly other Ipswitch products, allows remote attackers to bypass authentication and read logs via a logLogout action to FTPLogServer/login.asp followed by a request to FTPLogServer/LogViewer.asp with the localhostnull account…

  • CVE-2008-3734Aug 20, 2008
    risk 0.04cvss epss 0.14

    Format string vulnerability in Ipswitch WS_FTP Home 2007.0.0.2 and WS_FTP Professional 2007.1.0.0 allows remote FTP servers to cause a denial of service (application crash) or possibly execute arbitrary code via format string specifiers in a connection greeting (response).

  • CVE-2009-4775Apr 21, 2010
    risk 0.03cvss epss 0.06

    Format string vulnerability in Ipswitch WS_FTP Professional 12 before 12.2 allows remote attackers to cause a denial of service (crash) via format string specifiers in the status code portion of an HTTP response.

  • CVE-1999-1171Feb 2, 1999
    risk 0.03cvss epss 0.05

    IPswitch WS_FTP allows local users to gain additional privileges and modify or add mail accounts by setting the "flags" registry key to 1920.

  • CVE-2007-3823Jul 17, 2007
    risk 0.02cvss epss 0.25

    The Logging Server (Logsrv.exe) in IPSwitch WS_FTP 7.5.29.0 allows remote attackers to cause a denial of service (daemon crash) by sending a crafted packet containing a long string to port 5151/udp.

  • CVE-2008-5693Dec 19, 2008
    risk 0.00cvss epss 0.03

    Ipswitch WS_FTP Server Manager 6.1.0.0 and earlier, and possibly other Ipswitch products, might allow remote attackers to read the contents of custom ASP files in WSFTPSVR/ via a request with an appended dot character.

  • CVE-2008-0608Feb 6, 2008
    risk 0.00cvss epss 0.06

    The Logging Server (ftplogsrv.exe) 7.9.14.0 and earlier in IPSwitch WS_FTP 6.1 allows remote attackers to cause a denial of service (loss of responsiveness) via a large number of large packets to port 5151/udp, which causes the listening socket to terminate and prevents log…

  • CVE-2007-4555Aug 28, 2007
    risk 0.00cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in Ipswitch WS_FTP allows remote attackers to inject arbitrary web script or HTML via arguments to a valid command, which is not properly handled when it is displayed by the view log option in the administration interface. NOTE: this can…

  • CVE-2007-2213Apr 24, 2007
    risk 0.00cvss epss 0.05

    Unspecified vulnerability in the Initialize function in NetscapeFTPHandler in WS_FTP Home and Professional 2007 allows remote attackers to cause a denial of service (NULL dereference and application crash) via unspecified vectors related to "improper arguments."

  • CVE-2007-0665Feb 2, 2007
    risk 0.00cvss epss 0.03

    Format string vulnerability in the SCP module in Ipswitch WS_FTP 2007 Professional might allow remote attackers to execute arbitrary commands via format string specifiers in the filename, related to the SHELL WS_FTP script command.

  • CVE-2007-0330Jan 18, 2007
    risk 0.00cvss epss 0.03

    Buffer overflow in wsbho2k0.dll, as used by wsftpurl.exe, in Ipswitch WS_FTP 2007 Professional allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long ftp:// URL in an HTML document, and possibly other vectors.

  • CVE-2004-1884Mar 23, 2004
    risk 0.00cvss epss 0.06

    Ipswitch WS_FTP Server 4.0.2 has a backdoor XXSESS_MGRYY username with a default password, which allows remote attackers to gain access.

  • CVE-2002-1851Dec 31, 2002
    risk 0.00cvss epss 0.03

    Buffer overflow in WS_FTP Pro 7.5 allows remote attackers to execute code on a client system via unknown attack vectors.

  • CVE-1999-1078Jul 29, 1999
    risk 0.00cvss epss 0.02

    WS_FTP Pro 6.0 uses weak encryption for passwords in its initialization files, which allows remote attackers to easily decrypt the passwords and gain privileges.