CVE-2020-22428
Published May 5, 2021SolarWinds Serv-U before 15.1.6 Hotfix 3 is affected by Cross Site Scripting (XSS) via a directory name (entered by an admin) containing a JavaScript payload.
Vendor/product archive
11 CVEs tagged to solarwinds / serv-u_ftp_server — 3 Critical, 3 High, 5 Medium, 0 Low, 0 Unrated.
SolarWinds Serv-U before 15.1.6 Hotfix 3 is affected by Cross Site Scripting (XSS) via a directory name (entered by an admin) containing a JavaScript payload.
SolarWinds Serv-U FTP server before 15.2.1 does not validate an argument path.
SolarWinds Serv-U FTP server before 15.2.1 mishandles the CHMOD command.
SolarWinds Serv-U FTP server before 15.2.1 allows remote command execution.
A cross-site scripting (XSS) vulnerability exists in SolarWinds Serv-U FTP Server 15.1.7 in the email parameter, a different vulnerability than CVE-2018-19934 and CVE-2019-13182.
A stored cross-site scripting (XSS) vulnerability exists in the web UI of SolarWinds Serv-U FTP Server 15.1.7.
A CSV injection vulnerability exists in the web UI of SolarWinds Serv-U FTP Server v15.1.7.
A privilege escalation vulnerability exists in SolarWinds Serv-U before 15.1.7 for Linux.
The local management interface in SolarWinds Serv-U FTP Server 15.1.6.25 has incorrect access controls that permit local users to bypass authentication in the application and exec…
SolarWinds Serv-U FTP Server 15.1.6.25 has reflected cross-site scripting (XSS) in the Web management interface via URL path and HTTP POST parameter.
SolarWinds Serv-U FTP Server 15.1.6 allows remote authenticated users to execute arbitrary code by leveraging the Import feature and modifying a CSV file.