CVE-2020-14057
Summary
| CVE | CVE-2020-14057 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-07-01 17:15:00 UTC |
| Updated | 2020-07-08 13:18:00 UTC |
| Description | Monsta FTP 2.10.1 or below allows external control of paths used in filesystem operations. This allows attackers to read and write arbitrary local files, allowing an attacker to gain remote code execution in common deployments. |
Risk And Classification
Problem Types: CWE-610
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Monstaftp | Monsta Ftp | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Release Notes - Monsta FTP | MISC | www.monstaftp.com | Release Notes, Vendor Advisory |
| advisories/2019/SBA-ADV-20191203-01_Monsta_FTP_Arbitrary_File_Read_and_Write at public · sbaresearch/advisories · GitHub | MISC | github.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.