VYPR

Serv U FTP Server

by SolarWinds

CVEs (11)

  • CVE-2019-12181HigJun 17, 2019
    risk 0.65cvss 8.8epss 0.66

    A privilege escalation vulnerability exists in SolarWinds Serv-U before 15.1.7 for Linux.

  • CVE-2020-15543CriJul 5, 2020
    risk 0.64cvss 9.8epss 0.02

    SolarWinds Serv-U FTP server before 15.2.1 does not validate an argument path.

  • CVE-2020-15542CriJul 5, 2020
    risk 0.64cvss 9.8epss 0.02

    SolarWinds Serv-U FTP server before 15.2.1 mishandles the CHMOD command.

  • CVE-2020-15541CriJul 5, 2020
    risk 0.64cvss 9.8epss 0.07

    SolarWinds Serv-U FTP server before 15.2.1 allows remote command execution.

  • CVE-2018-19999HigJun 7, 2019
    risk 0.51cvss 7.8epss 0.01

    The local management interface in SolarWinds Serv-U FTP Server 15.1.6.25 has incorrect access controls that permit local users to bypass authentication in the application and execute code in the context of the Windows SYSTEM account, leading to privilege escalation. To exploit…

  • CVE-2018-15906HigMar 21, 2019
    risk 0.47cvss 7.2epss 0.08

    SolarWinds Serv-U FTP Server 15.1.6 allows remote authenticated users to execute arbitrary code by leveraging the Import feature and modifying a CSV file.

  • CVE-2019-13181MedDec 16, 2019
    risk 0.43cvss 6.5epss 0.03

    A CSV injection vulnerability exists in the web UI of SolarWinds Serv-U FTP Server v15.1.7.

  • CVE-2019-13182MedDec 16, 2019
    risk 0.36cvss 5.4epss 0.06

    A stored cross-site scripting (XSS) vulnerability exists in the web UI of SolarWinds Serv-U FTP Server 15.1.7.

  • CVE-2019-19829MedDec 18, 2019
    risk 0.35cvss 5.4epss 0.02

    A cross-site scripting (XSS) vulnerability exists in SolarWinds Serv-U FTP Server 15.1.7 in the email parameter, a different vulnerability than CVE-2018-19934 and CVE-2019-13182.

  • CVE-2018-19934MedMar 21, 2019
    risk 0.32cvss 4.8epss 0.05

    SolarWinds Serv-U FTP Server 15.1.6.25 has reflected cross-site scripting (XSS) in the Web management interface via URL path and HTTP POST parameter.

  • CVE-2020-22428MedMay 5, 2021
    risk 0.31cvss 4.8epss 0.01

    SolarWinds Serv-U before 15.1.6 Hotfix 3 is affected by Cross Site Scripting (XSS) via a directory name (entered by an admin) containing a JavaScript payload.