ghsa-6p46-7gq6-xc33
Vulnerability from github
Published
2022-05-24 17:10
Modified
2022-05-24 17:10
VLAI Severity ?
Details
An issue was discovered in Wing FTP Server 6.2.5 before February 2020. Due to insecure permissions when handling session cookies, a local user may view the contents of the session and session_admin directories, which expose active session cookies within the Wing FTP HTTP interface and administration panel. These cookies may be used to hijack user and administrative sessions, including the ability to execute Lua commands as root within the administration panel.
{ "affected": [], "aliases": [ "CVE-2020-9470" ], "database_specific": { "cwe_ids": [ "CWE-311" ], "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2020-03-07T01:15:00Z", "severity": "MODERATE" }, "details": "An issue was discovered in Wing FTP Server 6.2.5 before February 2020. Due to insecure permissions when handling session cookies, a local user may view the contents of the session and session_admin directories, which expose active session cookies within the Wing FTP HTTP interface and administration panel. These cookies may be used to hijack user and administrative sessions, including the ability to execute Lua commands as root within the administration panel.", "id": "GHSA-6p46-7gq6-xc33", "modified": "2022-05-24T17:10:23Z", "published": "2022-05-24T17:10:23Z", "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-9470" }, { "type": "WEB", "url": "https://www.hooperlabs.xyz/disclosures/cve-2020-9470.php" } ], "schema_version": "1.4.0", "severity": [] }
Loading…
Loading…
Sightings
Author | Source | Type | Date |
---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…