Provideserver

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 8
    Known Exploited: 0
    2
    Critical Level Threats
    4
    High Level Threats
    2
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2020-11701

    An issue was discovered in ProVide (formerly zFTPServer) through 13.1. CSRF exists in the User Web Interface, as demonstrated by granting filesystem access to the public for uploading and deleting files and directories.

    Last Modified: Nov 21, 2024
    Published: Apr 12, 2020

    CVE-2020-11702

    An issue was discovered in ProVide (formerly zFTPServer) through 13.1. The User Web Interface has Multiple Stored and Reflected XSS issues. Collaborate is Reflected via the filename parameter. Collaborate is Stored via the displayname parameter. Deletemultiple is Reflected via the files parameter. Share is Reflected via the target parameter. Share is Stored via the displayname parameter. Waitedit is Reflected via the Host header.

    Last Modified: Nov 21, 2024
    Published: Apr 12, 2020

    CVE-2020-11703

    An issue was discovered in ProVide (formerly zFTPServer) through 13.1. /ajax/GetInheritedProperties allows HTTP Response Splitting via the language parameter.

    Last Modified: Nov 21, 2024
    Published: Apr 12, 2020

    CVE-2020-11704

    An issue was discovered in ProVide (formerly zFTPServer) through 13.1. The Admin Web Interface has Multiple Stored and Reflected XSS. GetInheritedProperties is Reflected via the groups parameter. GetUserInfo is Reflected via POST data. SetUserInfo is Stored via the general parameter.

    Last Modified: Nov 21, 2024
    Published: Apr 12, 2020

    CVE-2020-11705

    An issue was discovered in ProVide (formerly zFTPServer) through 13.1. /ajax/ImportCertificate allows an attacker to load an arbitrary certificate in .pfx format or overwrite arbitrary files via the fileName parameter.

    Last Modified: Nov 21, 2024
    Published: Apr 12, 2020
    Items Per Page
    Provideserver Vulnerabilities & Security CVEs | CVE-DB