First published: Sun Mar 17 2019(Updated: )
SolarWinds Serv-U FTP Server 15.1.6.25 has reflected cross-site scripting (XSS) in the Web management interface via URL path and HTTP POST parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Solarwinds Serv-u Ftp Server | =15.1.6.25 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-19934 is medium with a severity value of 4.8.
The affected software for CVE-2018-19934 is SolarWinds Serv-U FTP Server version 15.1.6.25.
CVE-2018-19934 is a reflected cross-site scripting (XSS) vulnerability in the Web management interface of SolarWinds Serv-U FTP Server.
An attacker can exploit CVE-2018-19934 by manipulating the URL path and HTTP POST parameter in the Web management interface of SolarWinds Serv-U FTP Server.
Yes, here are some references for CVE-2018-19934: [1] http://packetstormsecurity.com/files/151474/SolarWinds-Serv-U-FTP-15.1.6.25-Cross-Site-Scripting.html [2] http://seclists.org/fulldisclosure/2019/Feb/5 [3] https://www.themissinglink.com.au/security-advisories-cve-2018-19934