PoC Index

CVE-2020-8635

HIGH 7.8EPSS 0.8%

Wing FTP Server v6.2.3 for Linux, macOS, and Solaris sets insecure permissions on installation directories and configuration files. This allows local users to arbitrarily create FTP users with full privileges, and escalate privileges within the operating system by modifying system files.

CVSS v3.1
7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
EPSS
0.81% chance of exploitation in the next 30 days, 54th percentile
Published
2020-03-06
Updated
2024-08-04

Proof-of-concept exploits (1)

References

Related