CVE-2020-37032: Wing FTP Server 6.3.8 - Remote Code Execution
Wing FTP Server 6.3.8 contains a remote code execution vulnerability in its Lua-based web console that allows authenticated users to execute system commands. Attackers can leverage the console to send POST requests with malicious commands that trigger operating system execution through the os.execute() function.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-37032?
CVE-2020-37032 is classified as a critical severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2020-37032?
To fix CVE-2020-37032, upgrade Wing FTP Server to the latest version which addresses this vulnerability.
Who is affected by CVE-2020-37032?
CVE-2020-37032 affects users of Wing FTP Server version 6.3.8, specifically those using its Lua-based web console.
What can attackers do with CVE-2020-37032?
Attackers exploiting CVE-2020-37032 can execute arbitrary system commands by sending crafted POST requests as authenticated users.
Is CVE-2020-37032 a local or remote vulnerability?
CVE-2020-37032 is a remote vulnerability, allowing exploitation over a network without physical access.