Vulnerabilities
Vulnerable Software
Coreftp:  Security Vulnerabilities
Core FTP / SFTP Server v2 Build 725 was discovered to allow unauthenticated attackers to cause a Denial of Service (DoS) via a crafted packet through the SSH service.
CVSS Score
5.5
EPSS Score
0.002
Published
2022-02-17
CoreFTP Server before 727 allows directory traversal (for file creation) by an authenticated attacker via ../ in an HTTP PUT request.
CVSS Score
6.5
EPSS Score
0.031
Published
2022-01-10
Buffer overflow vulnerability in Core FTP Server v2 Build 697, via a crafted username.
CVSS Score
7.5
EPSS Score
0.004
Published
2021-04-05
Buffer overflow vulnerability in Core FTP Server v1.2 Build 583, via a crafted username.
CVSS Score
9.8
EPSS Score
0.005
Published
2021-04-05
Buffer overflow in Core FTP LE v2.2 allows local attackers to cause a denial or service (crash) via a long string in the Setup->Users->Username editbox.
CVSS Score
5.5
EPSS Score
0.001
Published
2021-04-02
An issue was discovered in the SFTP Server component in Core FTP 2.0 Build 674. Using the MDTM FTP command, a remote attacker can use a directory traversal technique (..\..\) to browse outside the root directory to determine the existence of a file on the operating system, and its last modified date.
CVSS Score
5.3
EPSS Score
0.297
Published
2019-03-22
An issue was discovered in the SFTP Server component in Core FTP 2.0 Build 674. A directory traversal vulnerability exists using the SIZE command along with a \..\..\ substring, allowing an attacker to enumerate file existence based on the returned information.
CVSS Score
5.3
EPSS Score
0.203
Published
2019-03-22
The server in Core FTP 2.0 build 653 on 32-bit platforms allows remote attackers to cause a denial of service (daemon crash) via a crafted XRMD command.
CVSS Score
7.5
EPSS Score
0.198
Published
2019-01-02
Core FTP LE version 2.2 Build 1921 is prone to a buffer overflow vulnerability that may result in a DoS or remote code execution via a PASV response.
CVSS Score
9.8
EPSS Score
0.128
Published
2018-07-05
Multiple buffer overflows in Core FTP Server before 1.2 build 508 allow local users to gain privileges via vectors related to reading data from config.dat and Windows Registry.
CVSS Score
7.8
EPSS Score
0.001
Published
2018-03-20


Contact Us

Shodan ® - All rights reserved