CVE-2020-5195
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Reflected XSS through an IMG element in Cerberus FTP Server prior to versions 11.0.1 and 10.0.17 allows a remote attacker to execute arbitrary JavaScript or HTML via a crafted public folder URL. This occurs because of the folder_up.png IMG element not properly sanitizing user-inserted directory paths. The path modification must be done on a publicly shared folder for a remote attacker to insert arbitrary JavaScript or HTML. The vulnerability impacts anyone who clicks the malicious link crafted by the attacker.
Una vulnerabilidad de tipo XSS Reflejado por medio de un elemento IMG en Cerberus FTP Server versiones anteriores a la versión 11.0.1 y 10.0.17, permite a un atacante remoto ejecutar JavaScript o HTML arbitrario por medio de una URL de carpeta pública especialmente diseñada. Esto se produce debido a que el elemento IMG folder_up.png no sanea apropiadamente las rutas de directorio insertadas por el usuario. La modificación de ruta debe hacerse en una carpeta compartida públicamente para que un atacante remoto inserte JavaScript o HTML arbitrario. La vulnerabilidad impacta a cualquiera que haga clic en el enlace malicioso creado por parte del atacante.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-01-02 CVE Reserved
- 2020-01-13 CVE Published
- 2023-11-17 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://www.doyler.net/security-not-included/cerberus-ftp-vulnerabilities | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cerberusftp Search vendor "Cerberusftp" | Ftp Server Search vendor "Cerberusftp" for product "Ftp Server" | >= 10.0.0 < 10.0.17 Search vendor "Cerberusftp" for product "Ftp Server" and version " >= 10.0.0 < 10.0.17" | enterprise |
Affected
| ||||||
Cerberusftp Search vendor "Cerberusftp" | Ftp Server Search vendor "Cerberusftp" for product "Ftp Server" | >= 11.0.0 < 11.0.1 Search vendor "Cerberusftp" for product "Ftp Server" and version " >= 11.0.0 < 11.0.1" | enterprise |
Affected
|