Vulnerability Description
Wing FTP Server 6.3.8 contains a remote code execution vulnerability in its Lua-based web console that allows authenticated users to execute system commands. Attackers can leverage the console to send POST requests with malicious commands that trigger operating system execution through the os.execute() function.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Wftpserver | Wing Ftp Server | 6.3.8 |
Related Weaknesses (CWE)
References
- https://www.exploit-db.com/exploits/48676ExploitThird Party AdvisoryVDB Entry
- https://www.vulncheck.com/advisories/wing-ftp-server-remote-code-executionBroken Link
- https://www.wftpserver.com/Product
FAQ
What is CVE-2020-37032?
CVE-2020-37032 is a vulnerability with a CVSS score of 8.8 (HIGH). Wing FTP Server 6.3.8 contains a remote code execution vulnerability in its Lua-based web console that allows authenticated users to execute system commands. Attackers can leverage the console to send...
How severe is CVE-2020-37032?
CVE-2020-37032 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-37032?
Check the references section above for vendor advisories and patch information. Affected products include: Wftpserver Wing Ftp Server.