Rumpus
Products
1- 10 CVEs
Recent CVEs
10| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-46370 | Hig | 0.47 | 7.3 | 0.00 | Jan 12, 2023 | Rumpus - FTP server version 9.0.7.1 Improper Token Verification– vulnerability may allow bypassing identity verification. | ||
| CVE-2022-46369 | Med | 0.44 | 6.8 | 0.00 | Jan 12, 2023 | Rumpus - FTP server version 9.0.7.1 Persistent cross-site scripting (PXSS) – vulnerability may allow inserting scripts into unspecified input fields. | ||
| CVE-2022-46368 | Med | 0.44 | 6.8 | 0.00 | Jan 12, 2023 | Rumpus - FTP server version 9.0.7.1 Cross-site request forgery (CSRF) – vulnerability may allow unauthorized action on behalf of authenticated users. | ||
| CVE-2022-46367 | Med | 0.44 | 6.8 | 0.00 | Jan 12, 2023 | Rumpus - FTP server Cross-site request forgery (CSRF) – Privilege escalation vulnerability that may allow privilege escalation. | ||
| CVE-2022-39187 | Med | 0.44 | 6.8 | 0.00 | Jan 12, 2023 | Rumpus - FTP server version 9.0.7.1 has a Reflected cross-site scripting (RXSS) vulnerability through unspecified vectors. | ||
| CVE-2020-8514 | Med | 0.40 | 6.1 | 0.01 | Feb 2, 2020 | An issue was discovered in Rumpus 8.2.10 on macOS. By crafting a directory name, it is possible to activate JavaScript in the context of the web application after invoking the rename folder functionality. | ||
| CVE-2019-19668 | Med | 0.28 | 4.3 | 0.00 | Feb 10, 2020 | A CSRF vulnerability exists in the File Types component of Web File Manager in Rumpus FTP 8.2.9.1 that allows an attacker to add or delete the file types that are used on the server via RAPR/TriggerServerFunction.html. | ||
| CVE-2007-0019 | 0.03 | — | 0.04 | Jan 19, 2007 | Multiple heap-based buffer overflows in rumpusd in Rumpus 5.1 and earlier (1) allow remote authenticated users to execute arbitrary code via a long LIST command and other unspecified requests to the FTP service, and (2) allow remote attackers to execute arbitrary code via… | |||
| CVE-2007-0366 | 0.00 | — | 0.00 | Jan 19, 2007 | Untrusted search path vulnerability in Rumpus 5.1 and earlier allows local users to gain privileges via a modified PATH that points to a malicious ipfw program. | |||
| CVE-2007-0367 | 0.00 | — | 0.00 | Jan 19, 2007 | Rumpus 5.1 and earlier has weak permissions for certain files and directories under /usr/local/Rumpus, including the configuration file, which allows local users to have an unknown impact by creating, modifying, or deleting files. |
- risk 0.47cvss 7.3epss 0.00
Rumpus - FTP server version 9.0.7.1 Improper Token Verification– vulnerability may allow bypassing identity verification.
- risk 0.44cvss 6.8epss 0.00
Rumpus - FTP server version 9.0.7.1 Persistent cross-site scripting (PXSS) – vulnerability may allow inserting scripts into unspecified input fields.
- risk 0.44cvss 6.8epss 0.00
Rumpus - FTP server version 9.0.7.1 Cross-site request forgery (CSRF) – vulnerability may allow unauthorized action on behalf of authenticated users.
- risk 0.44cvss 6.8epss 0.00
Rumpus - FTP server Cross-site request forgery (CSRF) – Privilege escalation vulnerability that may allow privilege escalation.
- risk 0.44cvss 6.8epss 0.00
Rumpus - FTP server version 9.0.7.1 has a Reflected cross-site scripting (RXSS) vulnerability through unspecified vectors.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Rumpus 8.2.10 on macOS. By crafting a directory name, it is possible to activate JavaScript in the context of the web application after invoking the rename folder functionality.
- risk 0.28cvss 4.3epss 0.00
A CSRF vulnerability exists in the File Types component of Web File Manager in Rumpus FTP 8.2.9.1 that allows an attacker to add or delete the file types that are used on the server via RAPR/TriggerServerFunction.html.
- CVE-2007-0019Jan 19, 2007risk 0.03cvss —epss 0.04
Multiple heap-based buffer overflows in rumpusd in Rumpus 5.1 and earlier (1) allow remote authenticated users to execute arbitrary code via a long LIST command and other unspecified requests to the FTP service, and (2) allow remote attackers to execute arbitrary code via…
- CVE-2007-0366Jan 19, 2007risk 0.00cvss —epss 0.00
Untrusted search path vulnerability in Rumpus 5.1 and earlier allows local users to gain privileges via a modified PATH that points to a malicious ipfw program.
- CVE-2007-0367Jan 19, 2007risk 0.00cvss —epss 0.00
Rumpus 5.1 and earlier has weak permissions for certain files and directories under /usr/local/Rumpus, including the configuration file, which allows local users to have an unknown impact by creating, modifying, or deleting files.