Progress WS_FTP Server 8.8.5

CPE Details

Progress WS_FTP Server 8.8.5
8.8.5
2024-09-07
11h55 +00:00
2024-09-07
11h55 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:progress:ws_ftp_server:8.8.5:*:*:*:*:*:*:*

Informations

Vendor

progress

Product

ws_ftp_server

Version

8.8.5

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2024-7745 2024-08-28 16h31 +00:00 In WS_FTP Server versions before 8.8.8 (2022.0.8), a Missing Critical Step in Multi-Factor Authentication of the Web Transfer Module allows users to skip the second-factor verification and log in with username and password only.
8.1
High
CVE-2024-7744 2024-08-28 16h30 +00:00 In WS_FTP Server versions before 8.8.8 (2022.0.8), an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the Web Transfer Module allows File Discovery, Probe System Files, User-Controlled Filename, Path Traversal.   An authenticated file download flaw has been identified where a user can craft an API call that allows them to download a file from an arbitrary folder on the drive where that user host's root folder is located (by default this is C:)
6.5
Medium