Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface in Cerberus FTP Server before 5.0.5.0 allow remote attackers to hijack the authentication of administrators for requests that (1) add a user account or (2) reconfigure the state of the FTP service, as demonstrated by a request to usermanager/users/modify.
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ftp_server | Cerberusftp | * | 5.0.4.3 (including) |
Ftp_server | Cerberusftp | 1.0 (including) | 1.0 (including) |
Ftp_server | Cerberusftp | 1.01 (including) | 1.01 (including) |
Ftp_server | Cerberusftp | 1.1 (including) | 1.1 (including) |
Ftp_server | Cerberusftp | 1.2 (including) | 1.2 (including) |
Ftp_server | Cerberusftp | 1.02 (including) | 1.02 (including) |
Ftp_server | Cerberusftp | 1.03 (including) | 1.03 (including) |
Ftp_server | Cerberusftp | 1.5 (including) | 1.5 (including) |
Ftp_server | Cerberusftp | 1.05 (including) | 1.05 (including) |
Ftp_server | Cerberusftp | 1.6-beta (including) | 1.6-beta (including) |
Ftp_server | Cerberusftp | 1.7 (including) | 1.7 (including) |
Ftp_server | Cerberusftp | 1.22 (including) | 1.22 (including) |
Ftp_server | Cerberusftp | 1.71 (including) | 1.71 (including) |
Ftp_server | Cerberusftp | 2.0 (including) | 2.0 (including) |
Ftp_server | Cerberusftp | 2.0-beta1 (including) | 2.0-beta1 (including) |
Ftp_server | Cerberusftp | 2.0-beta2 (including) | 2.0-beta2 (including) |
Ftp_server | Cerberusftp | 2.0-beta3 (including) | 2.0-beta3 (including) |
Ftp_server | Cerberusftp | 2.0-beta4 (including) | 2.0-beta4 (including) |
Ftp_server | Cerberusftp | 2.1 (including) | 2.1 (including) |
Ftp_server | Cerberusftp | 2.01 (including) | 2.01 (including) |
Ftp_server | Cerberusftp | 2.02 (including) | 2.02 (including) |
Ftp_server | Cerberusftp | 2.2 (including) | 2.2 (including) |
Ftp_server | Cerberusftp | 2.02-beta (including) | 2.02-beta (including) |
Ftp_server | Cerberusftp | 2.2-beta1 (including) | 2.2-beta1 (including) |
Ftp_server | Cerberusftp | 2.2-beta2 (including) | 2.2-beta2 (including) |
Ftp_server | Cerberusftp | 2.2-beta3 (including) | 2.2-beta3 (including) |
Ftp_server | Cerberusftp | 2.3 (including) | 2.3 (including) |
Ftp_server | Cerberusftp | 2.4 (including) | 2.4 (including) |
Ftp_server | Cerberusftp | 2.4-beta1 (including) | 2.4-beta1 (including) |
Ftp_server | Cerberusftp | 2.4-beta2 (including) | 2.4-beta2 (including) |
Ftp_server | Cerberusftp | 2.4-beta3 (including) | 2.4-beta3 (including) |
Ftp_server | Cerberusftp | 2.11 (including) | 2.11 (including) |
Ftp_server | Cerberusftp | 2.11-beta (including) | 2.11-beta (including) |
Ftp_server | Cerberusftp | 2.11-beta2 (including) | 2.11-beta2 (including) |
Ftp_server | Cerberusftp | 2.15 (including) | 2.15 (including) |
Ftp_server | Cerberusftp | 2.15-beta (including) | 2.15-beta (including) |
Ftp_server | Cerberusftp | 2.16 (including) | 2.16 (including) |
Ftp_server | Cerberusftp | 2.21 (including) | 2.21 (including) |
Ftp_server | Cerberusftp | 2.22 (including) | 2.22 (including) |
Ftp_server | Cerberusftp | 2.23-beta (including) | 2.23-beta (including) |
Ftp_server | Cerberusftp | 2.31 (including) | 2.31 (including) |
Ftp_server | Cerberusftp | 2.32 (including) | 2.32 (including) |
Ftp_server | Cerberusftp | 2.41 (including) | 2.41 (including) |
Ftp_server | Cerberusftp | 2.42 (including) | 2.42 (including) |
Ftp_server | Cerberusftp | 2.43 (including) | 2.43 (including) |
Ftp_server | Cerberusftp | 2.44 (including) | 2.44 (including) |
Ftp_server | Cerberusftp | 2.45 (including) | 2.45 (including) |
Ftp_server | Cerberusftp | 2.46 (including) | 2.46 (including) |
Ftp_server | Cerberusftp | 2.47 (including) | 2.47 (including) |
Ftp_server | Cerberusftp | 2.48 (including) | 2.48 (including) |
Ftp_server | Cerberusftp | 2.49 (including) | 2.49 (including) |
Ftp_server | Cerberusftp | 2.50 (including) | 2.50 (including) |
Ftp_server | Cerberusftp | 3.0 (including) | 3.0 (including) |
Ftp_server | Cerberusftp | 3.0.1 (including) | 3.0.1 (including) |
Ftp_server | Cerberusftp | 3.0.2 (including) | 3.0.2 (including) |
Ftp_server | Cerberusftp | 3.0.3 (including) | 3.0.3 (including) |
Ftp_server | Cerberusftp | 3.0.4 (including) | 3.0.4 (including) |
Ftp_server | Cerberusftp | 3.0.5 (including) | 3.0.5 (including) |
Ftp_server | Cerberusftp | 3.0.6 (including) | 3.0.6 (including) |
Ftp_server | Cerberusftp | 3.0.7 (including) | 3.0.7 (including) |
Ftp_server | Cerberusftp | 3.0.7.1 (including) | 3.0.7.1 (including) |
Ftp_server | Cerberusftp | 3.0.8 (including) | 3.0.8 (including) |
Ftp_server | Cerberusftp | 3.1 (including) | 3.1 (including) |
Ftp_server | Cerberusftp | 3.1.0.3 (including) | 3.1.0.3 (including) |
Ftp_server | Cerberusftp | 3.1.0.4 (including) | 3.1.0.4 (including) |
Ftp_server | Cerberusftp | 3.1.0.5 (including) | 3.1.0.5 (including) |
Ftp_server | Cerberusftp | 3.1.1 (including) | 3.1.1 (including) |
Ftp_server | Cerberusftp | 3.1.2 (including) | 3.1.2 (including) |
Ftp_server | Cerberusftp | 3.1.3 (including) | 3.1.3 (including) |
Ftp_server | Cerberusftp | 3.1.3.1 (including) | 3.1.3.1 (including) |
Ftp_server | Cerberusftp | 3.1.4 (including) | 3.1.4 (including) |
Ftp_server | Cerberusftp | 4.0.0 (including) | 4.0.0 (including) |
Ftp_server | Cerberusftp | 4.0.0.6 (including) | 4.0.0.6 (including) |
Ftp_server | Cerberusftp | 4.0.0.8 (including) | 4.0.0.8 (including) |
Ftp_server | Cerberusftp | 4.0.0.9 (including) | 4.0.0.9 (including) |
Ftp_server | Cerberusftp | 4.0.0.11 (including) | 4.0.0.11 (including) |
Ftp_server | Cerberusftp | 4.0.1 (including) | 4.0.1 (including) |
Ftp_server | Cerberusftp | 4.0.1.1 (including) | 4.0.1.1 (including) |
Ftp_server | Cerberusftp | 4.0.2 (including) | 4.0.2 (including) |
Ftp_server | Cerberusftp | 4.0.2.2 (including) | 4.0.2.2 (including) |
Ftp_server | Cerberusftp | 5.0.0.0 (including) | 5.0.0.0 (including) |
Ftp_server | Cerberusftp | 5.0.0.1 (including) | 5.0.0.1 (including) |
Ftp_server | Cerberusftp | 5.0.0.2 (including) | 5.0.0.2 (including) |
Ftp_server | Cerberusftp | 5.0.0.3 (including) | 5.0.0.3 (including) |
Ftp_server | Cerberusftp | 5.0.0.4 (including) | 5.0.0.4 (including) |
Ftp_server | Cerberusftp | 5.0.0.5 (including) | 5.0.0.5 (including) |
Ftp_server | Cerberusftp | 5.0.0.6 (including) | 5.0.0.6 (including) |
Ftp_server | Cerberusftp | 5.0.0.7 (including) | 5.0.0.7 (including) |
Ftp_server | Cerberusftp | 5.0.1.0 (including) | 5.0.1.0 (including) |
Ftp_server | Cerberusftp | 5.0.1.1 (including) | 5.0.1.1 (including) |
Ftp_server | Cerberusftp | 5.0.1.2 (including) | 5.0.1.2 (including) |
Ftp_server | Cerberusftp | 5.0.2.0 (including) | 5.0.2.0 (including) |
Ftp_server | Cerberusftp | 5.0.3.0 (including) | 5.0.3.0 (including) |
Ftp_server | Cerberusftp | 5.0.3.1 (including) | 5.0.3.1 (including) |
Ftp_server | Cerberusftp | 5.0.4.0 (including) | 5.0.4.0 (including) |
Ftp_server | Cerberusftp | 5.0.4.1 (including) | 5.0.4.1 (including) |
Ftp_server | Cerberusftp | 5.0.4.2 (including) | 5.0.4.2 (including) |