CVE-2019-12146

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
11/06/2019
Last modified:
12/06/2019

Description

A Directory Traversal issue was discovered in SSHServerAPI.dll in Progress ipswitch WS_FTP Server 2018 before 8.6.1. Attackers have the ability to abuse a flaw in the SCP listener by crafting strings using specific patterns to write files and create directories outside of their authorized directory.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ipswitch:ws_ftp_server:*:*:*:*:*:*:*:* 8.6.1 (excluding)