Description



In WS_FTP Server versions prior to 8.7.4 and 8.8.2,

a SQL injection vulnerability exists in the WS_FTP Server manager interface. An attacker may be able to infer information about the structure and contents of the database and execute SQL statements that alter or delete database elements.

Published: 2023-09-27
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-44653 In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a SQL injection vulnerability exists in the WS_FTP Server manager interface. An attacker may be able to infer information about the structure and contents of the database and execute SQL statements that alter or delete database elements.
History

Mon, 23 Sep 2024 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Progress Ws Ftp Server
cve-icon MITRE

Status: PUBLISHED

Assigner: ProgressSoftware

Published:

Updated: 2024-09-23T15:07:01.880Z

Reserved: 2023-08-08T19:44:41.112Z

Link: CVE-2023-40046

cve-icon Vulnrichment

Updated: 2024-08-02T18:24:54.727Z

cve-icon NVD

Status : Modified

Published: 2023-09-27T15:18:58.103

Modified: 2024-11-21T08:18:35.697

Link: CVE-2023-40046

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses