CVE-2020-8634
07.03.2020, 00:15
Wing FTP Server v6.2.3 for Linux, macOS, and Solaris sets insecure permissions on files modified within the HTTP file management interface, resulting in files being saved with world-readable and world-writable permissions. If a sensitive system file were edited this way, a low-privilege user may escalate privileges to root.Enginsight
Vendor | Product | Version |
---|---|---|
wftpserver | wing_ftp_server | 6.2.3 |
wftpserver | wing_ftp_server | 6.2.3 |
wftpserver | wing_ftp_server | 6.2.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration