9
CVSSv2

CVE-2018-15906

Published: 21/03/2019 Updated: 03/10/2019
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 801
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

SolarWinds Serv-U FTP Server 15.1.6 allows remote authenticated users to execute arbitrary code by leveraging the Import feature and modifying a CSV file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

solarwinds serv-u ftp server 15.1.6

Exploits

SolarWinds Serv-U FTP Server version 1516 is vulnerable to privilege escalation from remote authenticated users by leveraging the CSV user import function This leads to obtaining remote code execution under the context of the Windows SYSTEM account in a default installation ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> Privilege Escalation + Remote Code Execution in SolarWinds Serv-U FTP Server <!--X-Subject-Header-End--> <!--X-Head-of ...