VendorsNetWinsurgeftp2.3a6
Vulnerabilities

NetWin SurgeFTP 2.3a6

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2013-4742
Buffer overflow in NetWin SurgeFTP before 23d2 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long string within the authentication request.
Published 2013-08-09 · Modified
7.5EPSS 0.042
CVE-2010-1068
Multiple cross-site scripting (XSS) vulnerabilities in surgeftpmgr.cgi in NetWin SurgeFTP 2.3a6 allow remote attackers to inject arbitrary web script or HTML via the (1) domainid or (2) classid parameter in a class action.
Published 2010-03-23 · Modified
4.3EPSS 0.011