CVE-2015-4108: CSRF
Multiple cross-site request forgery (CSRF) vulnerabilities in Wing FTP Server before 4.4.7 allow remote attackers to hijack the authentication of administrators for requests that (1) execute arbitrary code via a crafted request to adminluascript.html or (2) add a domain administrator via a crafted request to adminaddadmin.html.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-4108?
CVE-2015-4108 is considered a high severity vulnerability due to its potential to allow remote attackers to hijack administrative authentication.
How do I fix CVE-2015-4108?
To fix CVE-2015-4108, upgrade Wing FTP Server to version 4.4.7 or later.
What types of attacks are possible due to CVE-2015-4108?
CVE-2015-4108 allows for cross-site request forgery (CSRF) attacks that can execute arbitrary code or add a domain administrator.
Which versions of Wing FTP Server are affected by CVE-2015-4108?
Wing FTP Server versions prior to 4.4.7 are affected by CVE-2015-4108.
Who is impacted by CVE-2015-4108?
Administrators of Wing FTP Server are primarily impacted by the CVE-2015-4108 vulnerability.