VendorsProgressws_ftp_serverany version
Vulnerabilities

Progress WS_FTP Server any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

15CVEs
CVE-2023-40044
WS_FTP Server Ad Hoc Transfer Module .NET Deserialization Vulnerability
Published 2023-09-27 · Analyzed
10.0KEVEPSS 0.902
CVE-2023-42657
WS_FTP Server Directory Traversal
Published 2023-09-27 · Modified
9.9EPSS 0.170
CVE-2023-42659
WS_FTP Server Arbitrary File Upload
Published 2023-11-07 · Modified
9.1EPSS 0.009
CVE-2023-40045
WS_FTP Server Ad Hoc Transfer Module Reflected Cross-Site Scripting Vulnerability
Published 2023-09-27 · Modified
8.3EPSS 0.009
CVE-2023-40047
WS_FTP Server Stored Cross-Site Scripting Vulnerability
Published 2023-09-27 · Modified
8.3EPSS 0.004
CVE-2023-40046
WS_FTP Server SQL Injection via Administrative Interface
Published 2023-09-27 · Modified
8.2EPSS 0.009
CVE-2024-7745
Multi-Factor Authentication Bypass in Progress WS_FTP Server
Published 2024-08-28 · Analyzed
8.1EPSS 0.004
CVE-2024-1474
WS_FTP Server Reflected Cross-Site Scripting in Administrative Interface
Published 2024-02-21 · Analyzed
7.5EPSS 0.005
CVE-2023-24029
In Progress WS_FTP Server before 8.8, it is possible for a host administrator to elevate their privileges via the administrative interface due to insufficient authorization controls applied on user modification workflows.
Published 2023-02-03 · Modified
7.2EPSS 0.009
CVE-2023-40048
WS_FTP Server Cross-Site Request Forgery (CSRF) Vulnerability
Published 2023-09-27 · Modified
6.8EPSS 0.004
CVE-2006-4847
Multiple buffer overflows in Ipswitch WS_FTP Server 5.05 before Hotfix 1 allow remote authenticated users to execute arbitrary code via long (1) XCRC, (2) XSHA1, or (3) XMD5 commands.
Published 2006-09-19 · Modified
6.52 PoCEPSS 0.853
CVE-2024-7744
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Progress WS_FTP Server
Published 2024-08-28 · Analyzed
6.5EPSS 0.007
CVE-2019-12143
A Directory Traversal issue was discovered in SSHServerAPI.dll in Progress ipswitch WS_FTP Server 2018 before 8.6.1. An attacker can supply a string using special patterns via the SCP protocol to disclose WS_FTP usernames as well as filenames.
Published 2019-06-11 · Modified
5.3EPSS 0.020
CVE-2023-40049
WS_FTP Server Information Disclosure via Directory Listing
Published 2023-09-27 · Modified
5.3EPSS 0.007
CVE-2006-5001
Unspecified vulnerability in the log analyzer in WS_FTP Server 5.05 before Hotfix 1, and possibly other versions down to 5.0, prevents certain sensitive information from being displayed in the (1) Files and (2) Summary tabs. NOTE: in the early publication of this identifier on 20060926, the description was used for the wrong issue.
Published 2006-09-26 · Modified
5.0EPSS 0.319