In WS_FTP Server versions prior to 8.7.4 and 8.8.2,

a SQL injection vulnerability exists in the WS_FTP Server manager interface. An attacker may be able to infer information about the structure and contents of the database and execute SQL statements that alter or delete database elements.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-44653 In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a SQL injection vulnerability exists in the WS_FTP Server manager interface. An attacker may be able to infer information about the structure and contents of the database and execute SQL statements that alter or delete database elements.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 23 Sep 2024 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: ProgressSoftware

Published:

Updated: 2024-09-23T15:07:01.880Z

Reserved: 2023-08-08T19:44:41.112Z

Link: CVE-2023-40046

cve-icon Vulnrichment

Updated: 2024-08-02T18:24:54.727Z

cve-icon NVD

Status : Modified

Published: 2023-09-27T15:18:58.103

Modified: 2024-11-21T08:18:35.697

Link: CVE-2023-40046

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses