ZeroHour

CVE-2017-17933

PoC
CVSS 3.1
6.1 medium
EPSS
<1%p59
Published
()
Modified
Description

cgi/surgeftpmgr.cgi (aka the Web Manager interface on TCP port 7021 or 9021) in NetWin SurgeFTP version 23f2 has XSS via the classid, domainid, or username parameter.

Vendors
netwin
Products
surgeftp
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.