Vulnerabilities
Vulnerable Software
SolarWinds Serv-U FTP server before 15.2.1 allows remote command execution.
CVSS Score
9.8
EPSS Score
0.212
Published
2020-07-05
SolarWinds Serv-U FTP server before 15.2.1 mishandles the CHMOD command.
CVSS Score
9.8
EPSS Score
0.044
Published
2020-07-05
SolarWinds Serv-U FTP server before 15.2.1 does not validate an argument path.
CVSS Score
9.8
EPSS Score
0.044
Published
2020-07-05
The local management interface in SolarWinds Serv-U FTP Server 15.1.6.25 has incorrect access controls that permit local users to bypass authentication in the application and execute code in the context of the Windows SYSTEM account, leading to privilege escalation. To exploit this vulnerability, an attacker must have local access the the host running Serv-U, and a Serv-U administrator have an active management console session.
CVSS Score
7.8
EPSS Score
0.001
Published
2019-06-07
SolarWinds Serv-U FTP Server 15.1.6.25 has reflected cross-site scripting (XSS) in the Web management interface via URL path and HTTP POST parameter.
CVSS Score
4.8
EPSS Score
0.018
Published
2019-03-21


Contact Us

Shodan ® - All rights reserved