Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
crushftp crushftp vulnerabilities and exploits
(subscribe to this query)
6.1
CVSSv3
CVE-2017-14037
CrushFTP prior to 7.8.0 and 8.x prior to 8.2.0 has an HTTP header vulnerability.
Crushftp Crushftp 8.0.2
Crushftp Crushftp 8.0.3
Crushftp Crushftp 8.1.0
Crushftp Crushftp 8.0.4
Crushftp Crushftp
6.1
CVSSv3
CVE-2017-14036
CrushFTP prior to 7.8.0 and 8.x prior to 8.2.0 has XSS.
Crushftp Crushftp 8.0.2
Crushftp Crushftp 8.0.3
Crushftp Crushftp 8.1.0
Crushftp Crushftp 8.0.4
Crushftp Crushftp
6.1
CVSSv3
CVE-2017-14038
CrushFTP prior to 7.8.0 and 8.x prior to 8.2.0 has a redirect vulnerability.
Crushftp Crushftp 8.0.2
Crushftp Crushftp 8.0.3
Crushftp Crushftp 8.1.0
Crushftp Crushftp 8.0.4
Crushftp Crushftp
9.8
CVSSv3
CVE-2017-14035
CrushFTP 8.x prior to 8.2.0 has a serialization vulnerability.
Crushftp Crushftp 8.0.2
Crushftp Crushftp 8.0.3
Crushftp Crushftp 8.1.0
Crushftp Crushftp 8.0.4
10
CVSSv3
CVE-2024-4040
A server side template injection vulnerability in CrushFTP in all versions prior to 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote malicious users to read files from the filesystem outside of the VFS Sandbox, bypass authentication to gain administrative access, ...
Crushftp Crushftp
16 Github repositories
1 Article
9.8
CVSSv3
CVE-2023-43177
CrushFTP before 10.5.1 is vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes.
Crushftp Crushftp
2 Github repositories
2 Articles
6.1
CVSSv3
CVE-2018-18288
CrushFTP up to and including 8.3.0 is vulnerable to credentials theft via URL redirection.
Crushftp Crushftp
4.8
CVSSv3
CVE-2021-44076
An issue exists in CrushFTP 9. The creation of a new user through the /WebInterface/UserManager/ interface allows an attacker, with access to the administration panel, to perform Stored Cross-Site Scripting (XSS). The payload can be executed in multiple scenarios, for example whe...
Crushftp Crushftp
NA
CVE-2001-0582
Ben Spink CrushFTP FTP Server 2.1.6 and previous versions allows a local malicious user to access arbitrary files via a '..' (dot dot) attack, or variations, in (1) GET, (2) CD, (3) NLST, (4) SIZE, (5) RETR.
Ben Spink Crushftp Ftp Server 2.1.4
Ben Spink Crushftp Ftp Server
5.9
CVSSv3
CVE-2023-48795
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH prior to 9.6 and other products, allows remote malicious users to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may conseque...
Openbsd Openssh
Putty Putty
Filezilla-project Filezilla Client
Microsoft Powershell
Panic Transmit 5
Panic Nova
Roumenpetrov Pkixssh
Winscp Winscp
Bitvise Ssh Client
Bitvise Ssh Server
Lancom-systems Lcos
Lancom-systems Lcos Fx -
Lancom-systems Lcos Lx -
Lancom-systems Lcos Sx 5.20
Lancom-systems Lcos Sx 4.20
Lancom-systems Lanconfig -
Vandyke Securecrt
Libssh Libssh
Net-ssh Net-ssh 7.2.0
Ssh2 Project Ssh2
Proftpd Proftpd
Freebsd Freebsd
9 Github repositories
1 Article
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
type confusion
IMAP
CVE-2024-36103
CVE-2024-28995
CVE-2024-37325
CVE-2024-30078
CVE-2024-30082
SQL injection
CVE-2024-30052
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »