Solarwinds
Solarwinds Serv-u FTP Server: vulnerabilidades y CVE
Solarwinds Serv-u FTP Server tiene 11 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE11
Últimos 12 meses0
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2020-22428 | Media (4.8) | 1.2% | — | 5 may 2021 | SolarWinds Serv-U before 15.1.6 Hotfix 3 is affected by Cross Site Scripting (XSS) via a directory name (entered by an admin) containing a JavaScript payload. |
| CVE-2020-15543 | Crítica (9.8) | 1.6% | — | 5 jul 2020 | SolarWinds Serv-U FTP server before 15.2.1 does not validate an argument path. |
| CVE-2020-15542 | Crítica (9.8) | 1.6% | — | 5 jul 2020 | SolarWinds Serv-U FTP server before 15.2.1 mishandles the CHMOD command. |
| CVE-2020-15541 | Crítica (9.8) | 7.0% | — | 5 jul 2020 | SolarWinds Serv-U FTP server before 15.2.1 allows remote command execution. |
| CVE-2019-19829 | Media (5.4) | 2.3% | — | 18 dic 2019 | A cross-site scripting (XSS) vulnerability exists in SolarWinds Serv-U FTP Server 15.1.7 in the email parameter, a different vulnerability than CVE-2018-19934 and CVE-2019-13182. |
| CVE-2019-13182 | Media (5.4) | 6.4% | — | 16 dic 2019 | A stored cross-site scripting (XSS) vulnerability exists in the web UI of SolarWinds Serv-U FTP Server 15.1.7. |
| CVE-2019-13181 | Media (6.5) | 3.2% | — | 16 dic 2019 | A CSV injection vulnerability exists in the web UI of SolarWinds Serv-U FTP Server v15.1.7. |
| CVE-2019-12181 | Alta (8.8) | 66% | — | 17 jun 2019 | A privilege escalation vulnerability exists in SolarWinds Serv-U before 15.1.7 for Linux. |
| CVE-2018-19999 | Alta (7.8) | 0.60% | — | 7 jun 2019 | The local management interface in SolarWinds Serv-U FTP Server 15.1.6.25 has incorrect access controls that permit local users to bypass authentication in the application and execute code in the context of the Windows… |
| CVE-2018-19934 | Media (4.8) | 5.4% | — | 21 mar 2019 | SolarWinds Serv-U FTP Server 15.1.6.25 has reflected cross-site scripting (XSS) in the Web management interface via URL path and HTTP POST parameter. |
| CVE-2018-15906 | Alta (7.2) | 8.1% | — | 21 mar 2019 | SolarWinds Serv-U FTP Server 15.1.6 allows remote authenticated users to execute arbitrary code by leveraging the Import feature and modifying a CSV file. |