CVE Database
/

CVE-2012-10028

Back to search

CVE-2012-10028

Published: Aug 5, 2025

Modified: May 15, 2026

PUBLISHED

Description

Netwin SurgeFTP version 23c8 and prior contains a vulnerability in its web-based administrative console that allows authenticated users to execute arbitrary system commands via crafted POST requests to `surgeftpmgr.cgi`. This can lead to full remote code execution on the underlying system.

VendorProductVersions

Netwin

SurgeFTP

affected
0 - <= 23c8

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now