VendorsSolarwindsserv-u_ftp_serverall versions
Vulnerabilities

Solarwinds Serv-U FTP Server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

11CVEs
CVE-2020-15541
SolarWinds Serv-U FTP server before 15.2.1 allows remote command execution.
Published 2020-07-05 · Modified
9.8EPSS 0.070
CVE-2020-15542
SolarWinds Serv-U FTP server before 15.2.1 mishandles the CHMOD command.
Published 2020-07-05 · Modified
9.8EPSS 0.016
CVE-2020-15543
SolarWinds Serv-U FTP server before 15.2.1 does not validate an argument path.
Published 2020-07-05 · Modified
9.8EPSS 0.016
CVE-2018-15906
SolarWinds Serv-U FTP Server 15.1.6 allows remote authenticated users to execute arbitrary code by leveraging the Import feature and modifying a CSV file.
Published 2019-03-17 · Modified
9.0EPSS 0.081
CVE-2019-12181
A privilege escalation vulnerability exists in SolarWinds Serv-U before 15.1.7 for Linux.
Published 2019-06-17 · Modified
8.83 PoCEPSS 0.660
CVE-2018-19999
The local management interface in SolarWinds Serv-U FTP Server 15.1.6.25 has incorrect access controls that permit local users to bypass authentication in the application and execute code in the context of the Windows SYSTEM account, leading to privilege escalation. To exploit this vulnerability, an attacker must have local access the the host running Serv-U, and a Serv-U administrator have an active management console session.
Published 2019-06-07 · Modified
7.8EPSS 0.006
CVE-2019-13181
A CSV injection vulnerability exists in the web UI of SolarWinds Serv-U FTP Server v15.1.7.
Published 2019-12-16 · Modified
6.5EPSS 0.032
CVE-2019-13182
A stored cross-site scripting (XSS) vulnerability exists in the web UI of SolarWinds Serv-U FTP Server 15.1.7.
Published 2019-12-16 · Modified
5.4EPSS 0.064
CVE-2019-19829
A cross-site scripting (XSS) vulnerability exists in SolarWinds Serv-U FTP Server 15.1.7 in the email parameter, a different vulnerability than CVE-2018-19934 and CVE-2019-13182.
Published 2019-12-18 · Modified
5.4EPSS 0.023
CVE-2018-19934
SolarWinds Serv-U FTP Server 15.1.6.25 has reflected cross-site scripting (XSS) in the Web management interface via URL path and HTTP POST parameter.
Published 2019-03-17 · Modified
4.8EPSS 0.054
CVE-2020-22428
SolarWinds Serv-U before 15.1.6 Hotfix 3 is affected by Cross Site Scripting (XSS) via a directory name (entered by an admin) containing a JavaScript payload.
Published 2021-05-05 · Modified
4.8EPSS 0.012