CVE Database
/

CVE-2007-3769

Back to search

CVE-2007-3769

Published: Jul 15, 2007

Modified: Aug 7, 2024

PUBLISHED

Description

Cross-site scripting (XSS) vulnerability in the mirrored server management interface in SurgeFTP 2.3a1 allows user-assisted, remote FTP servers to inject arbitrary web script or HTML via a malformed response without a status code, which is reflected to the user in the resulting error message. NOTE: this can be leveraged for root access via a sequence of steps involving web script that creates a new FTP user account.

VendorProductVersions

n/a

n/a

affected
n/a

References

26061
third-party-advisory
x_refsource_SECUNIA
surgeftp-error-xss(35378)
vdb-entry
x_refsource_XF
ADV-2007-2528
vdb-entry
x_refsource_VUPEN
37911
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now