CVE-2017-17933
PoC —CVSS 3.1
6.1 medium
EPSS
<1%p59
Published
()
Modified
Description
cgi/surgeftpmgr.cgi (aka the Web Manager interface on TCP port 7021 or 9021) in NetWin SurgeFTP version 23f2 has XSS via the classid, domainid, or username parameter.
- Vendors
- netwin
- Products
- surgeftp
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.