NetWin SurgeFTP Multiple Remote Vulnerabilities
BID:24892
Info
NetWin SurgeFTP Multiple Remote Vulnerabilities
| Bugtraq ID: | 24892 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 10 2007 12:00AM |
| Updated: | Jul 13 2007 04:46PM |
| Credit: | Nico Leidecker of Portcullis Computer Security reported these issues. |
| Vulnerable: |
NetWin SurgeFTP 2.3a1 |
| Not Vulnerable: | |
Discussion
NetWin SurgeFTP Multiple Remote Vulnerabilities
SurgeFTP is prone to multiple remote vulnerabilities that include an HTML-injection issue and a denial-of-service vulnerability.
These issues reportedly affect SurgeFTP 2.3a1; other versions may be vulnerable as well.
SurgeFTP is prone to multiple remote vulnerabilities that include an HTML-injection issue and a denial-of-service vulnerability.
These issues reportedly affect SurgeFTP 2.3a1; other versions may be vulnerable as well.
Exploit / POC
NetWin SurgeFTP Multiple Remote Vulnerabilities
An exploit is not required because attackers can use command-line utilities and a browser.
An exploit is not required because attackers can use command-line utilities and a browser.
Solution / Fix
NetWin SurgeFTP Multiple Remote Vulnerabilities
Solution:
Reports indicate that the vendor has addressed these issues, but Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reports indicate that the vendor has addressed these issues, but Symantec has not confirmed this. Please contact the vendor for more information.
References
NetWin SurgeFTP Multiple Remote Vulnerabilities
References:
References:
- Portcullis Security Advisory 06-061 (Portcullis Computer Security Limited)
- Portcullis Security Advisory 06-062 (Portcullis Computer Security Limited)
- SurgeFTP Homepage (NetWin)