CVE-2024-7744

CVSS V2 None CVSS V3 None
Description
In WS_FTP Server versions before 8.8.8 (2022.0.8), an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the Web Transfer Module allows File Discovery, Probe System Files, User-Controlled Filename, Path Traversal.   An authenticated file download flaw has been identified where a user can craft an API call that allows them to download a file from an arbitrary folder on the drive where that user host's root folder is located (by default this is C:)
Overview
  • CVE ID
  • CVE-2024-7744
  • Assigner
  • ProgressSoftware
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-08-28T16:30:14.787Z
  • Last Modified Date
  • 2024-08-28T17:50:10.933Z
History
Created Old Value New Value Data Type Notes
2024-08-29 13:04:13 Added to TrackCVE