The administrative interface (surgeftpmgr.cgi) for SurgeFTP Server 1.0b through 2.2k1 allows remote attackers to cause a temporary denial of service (crash) via requests with two percent (%) signs in the CMD parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Surgeftp | Netwin | 1.0b (including) | 1.0b (including) |
Surgeftp | Netwin | 2.0a (including) | 2.0a (including) |
Surgeftp | Netwin | 2.0b (including) | 2.0b (including) |
Surgeftp | Netwin | 2.0c (including) | 2.0c (including) |
Surgeftp | Netwin | 2.0d (including) | 2.0d (including) |
Surgeftp | Netwin | 2.0e (including) | 2.0e (including) |
Surgeftp | Netwin | 2.0f (including) | 2.0f (including) |
Surgeftp | Netwin | 2.2k1 (including) | 2.2k1 (including) |