CVE Vulnerabilities

CVE-2004-2318

Published: Dec 31, 2004 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The administrative interface (surgeftpmgr.cgi) for SurgeFTP Server 1.0b through 2.2k1 allows remote attackers to cause a temporary denial of service (crash) via requests with two percent (%) signs in the CMD parameter.

Affected Software

NameVendorStart VersionEnd Version
SurgeftpNetwin1.0b (including)1.0b (including)
SurgeftpNetwin2.0a (including)2.0a (including)
SurgeftpNetwin2.0b (including)2.0b (including)
SurgeftpNetwin2.0c (including)2.0c (including)
SurgeftpNetwin2.0d (including)2.0d (including)
SurgeftpNetwin2.0e (including)2.0e (including)
SurgeftpNetwin2.0f (including)2.0f (including)
SurgeftpNetwin2.2k1 (including)2.2k1 (including)

References