VYPR
Vendor

SurgeFTP

Products
2
CVEs
4
Across products
4
Status
Private

Products

2

Recent CVEs

4
  • CVE-2007-3769Jul 15, 2007
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in the mirrored server management interface in SurgeFTP 2.3a1 allows user-assisted, remote FTP servers to inject arbitrary web script or HTML via a malformed response without a status code, which is reflected to the user in the resulting…

  • CVE-2007-3768Jul 15, 2007
    risk 0.00cvss epss 0.02

    The mirror mechanism in SurgeFTP 2.3a1 allows user-assisted, remote FTP servers to cause a denial of service (restart) via a malformed response to a PASV command.

  • CVE-2005-1034May 2, 2005
    risk 0.00cvss epss 0.02

    SurgeFTP 2.2m1 allows remote attackers to cause a denial of service (application hang) via the LEAK command.

  • CVE-2004-2318Dec 31, 2004
    risk 0.00cvss epss 0.02

    The administrative interface (surgeftpmgr.cgi) for SurgeFTP Server 1.0b through 2.2k1 allows remote attackers to cause a temporary denial of service (crash) via requests with two percent (%) signs in the CMD parameter.