cve,link,title,description,vendor,products,score,severity,epss,cisa,cisa_published,article,ransomware,exploited,exploited_date,poc,trended,trended_no_1,trended_no_1_date,published,trended_score CVE-2022-38106,https://securityvulnerability.io/vulnerability/CVE-2022-38106,"Cross-Site Scripting Vulnerability in Serv-U Web Client "," This vulnerability happens in the web client versions 15.3.0 to Serv-U 15.3.1. This vulnerability affects the directory creation function. ",Solarwinds,Serv-u File Server,5.4,MEDIUM,0.0006200000061653554,false,,false,false,false,,,false,false,,2022-12-16T00:00:00.000Z,0 CVE-2021-35211,https://securityvulnerability.io/vulnerability/CVE-2021-35211,Serv-U Remote Memory Escape Vulnerability,"Microsoft discovered a remote code execution (RCE) vulnerability in the SolarWinds Serv-U product utilizing a Remote Memory Escape Vulnerability. If exploited, a threat actor may be able to gain privileged access to the machine hosting Serv-U Only. SolarWinds Serv-U Managed File Transfer and Serv-U Secure FTP for Windows before 15.2.3 HF2 are affected by this vulnerability.",Solarwinds,Serv-u Managed File Transfer Server And Serv-u Secured Ftp,10,CRITICAL,0.9345800280570984,true,2021-11-03T00:00:00.000Z,false,true,true,2021-11-03T00:00:00.000Z,true,false,false,,2021-07-14T21:15:00.000Z,0 CVE-2021-25179,https://securityvulnerability.io/vulnerability/CVE-2021-25179,Cross Site Scripting in SolarWinds Serv-U Software,"SolarWinds Serv-U prior to version 15.2 is susceptible to an XSS vulnerability that occurs via the manipulation of the HTTP Host header. This security risk can potentially allow an attacker to execute malicious scripts in the context of an affected user's session, leading to unauthorized actions or data exposure. Users are advised to upgrade to a patched version to mitigate these security threats.",Solarwinds,Serv-u File Server,6.1,MEDIUM,0.0016400000313296914,false,,false,false,false,,,false,false,,2021-05-05T02:40:13.000Z,0 CVE-2011-4800,https://securityvulnerability.io/vulnerability/CVE-2011-4800,,"Directory traversal vulnerability in Serv-U FTP Server before 11.1.0.5 allows remote authenticated users to read and write arbitrary files, and list and create arbitrary directories, via a ""..:/"" (dot dot colon forward slash) in the (1) list, (2) put, or (3) get commands.",Solarwinds,Serv-u File Server,,,0.01623000018298626,false,,false,false,false,,,false,false,,2011-12-14T00:55:00.000Z,0 CVE-2009-4815,https://securityvulnerability.io/vulnerability/CVE-2009-4815,,Directory traversal vulnerability in Serv-U before 9.2.0.1 allows remote authenticated users to read arbitrary files via unspecified vectors.,Solarwinds,Serv-u File Server,,,0.0017800000496208668,false,,false,false,false,,,false,false,,2010-04-27T15:00:00.000Z,0 CVE-2009-4006,https://securityvulnerability.io/vulnerability/CVE-2009-4006,,"Stack-based buffer overflow in the TEA decoding algorithm in RhinoSoft Serv-U FTP server 7.0.0.1, 9.0.0.5, and other versions before 9.1.0.0 allows remote attackers to execute arbitrary code via a long hexadecimal string.",Solarwinds,Serv-u File Server,,,0.9392399787902832,false,,false,false,false,,,false,false,,2009-11-20T11:00:00.000Z,0 CVE-2009-3655,https://securityvulnerability.io/vulnerability/CVE-2009-3655,,"Rhino Software Serv-U 7.0.0.1 through 8.2.0.3 allows remote attackers to cause a denial of service (server crash) via unspecified vectors related to the ""SITE SET TRANSFERPROGRESS ON"" FTP command.",Solarwinds,Serv-u File Server,,,0.0063299997709691525,false,,false,false,false,,,false,false,,2009-10-09T14:18:00.000Z,0 CVE-2009-1031,https://securityvulnerability.io/vulnerability/CVE-2009-1031,,Directory traversal vulnerability in the FTP server in Rhino Software Serv-U File Server 7.0.0.1 through 7.4.0.1 allows remote attackers to create arbitrary directories via a \.. (backslash dot dot) in an MKD request.,Solarwinds,Serv-u File Server,,,0.6480699777603149,false,,false,false,false,,,false,false,,2009-03-20T00:00:00.000Z,0 CVE-2009-0967,https://securityvulnerability.io/vulnerability/CVE-2009-0967,,The FTP server in Serv-U 7.0.0.1 through 7.4.0.1 allows remote authenticated users to cause a denial of service (service hang) via a large number of SMNT commands without an argument.,Solarwinds,Serv-u File Server,,,0.02384999953210354,false,,false,false,false,,,false,false,,2009-03-19T10:00:00.000Z,0 CVE-2008-4500,https://securityvulnerability.io/vulnerability/CVE-2008-4500,,"Serv-U 7.0.0.1 through 7.3, including 7.2.0.1, allows remote authenticated users to cause a denial of service (CPU consumption) via a crafted stou command, probably related to MS-DOS device names, as demonstrated using ""con:1"".",Solarwinds,Serv-u File Server,,,0.03061000071465969,false,,false,false,false,,,false,false,,2008-10-09T00:00:00.000Z,0 CVE-2008-4501,https://securityvulnerability.io/vulnerability/CVE-2008-4501,,"Directory traversal vulnerability in the FTP server in Serv-U 7.0.0.1 through 7.3, including 7.2.0.1, allows remote authenticated users to overwrite or create arbitrary files via a ..\ (dot dot backslash) in the RNTO command.",Solarwinds,Serv-u File Server,,,0.02379000000655651,false,,false,false,false,,,false,false,,2008-10-09T00:00:00.000Z,0 CVE-2008-3731,https://securityvulnerability.io/vulnerability/CVE-2008-3731,,"Unspecified vulnerability in Serv-U File Server 7.0.0.1, and other versions before 7.2.0.1, allows remote authenticated users to cause a denial of service (daemon crash) via an SSH session with SFTP commands for directory creation and logging.",Solarwinds,Serv-u File Server,,,0.0032500000670552254,false,,false,false,false,,,false,false,,2008-08-20T16:00:00.000Z,0 CVE-2005-3467,https://securityvulnerability.io/vulnerability/CVE-2005-3467,,"Serv-U FTP Server before 6.1.0.4 allows attackers to cause a denial of service (crash) via (1) malformed packets and possibly other unspecified issues with unknown impact and attack vectors including (2) use of ""~"" in a pathname, and (3) memory consumption of the daemon. NOTE: it is not clear whether items (2) and above are vulnerabilities.",Solarwinds,Serv-u File Server,,,0.004189999774098396,false,,false,false,false,,,false,false,,2005-11-02T23:00:00.000Z,0 CVE-2004-2111,https://securityvulnerability.io/vulnerability/CVE-2004-2111,,Stack-based buffer overflow in the site chmod command in Serv-U FTP Server before 4.2 allows remote attackers to execute arbitrary code via a long filename.,Solarwinds,Serv-u File Server,,,0.9673600196838379,false,,false,false,false,,,false,false,,2004-12-31T05:00:00.000Z,0 CVE-2004-2533,https://securityvulnerability.io/vulnerability/CVE-2004-2533,,"Serv-U FTP Server 4.1 (possibly 4.0) allows remote attackers to cause a denial of service (application crash) via a SITE CHMOD command with a ""\\...\"" followed by a short string, causing partial memory corruption, a different vulnerability than CVE-2004-2111.",Solarwinds,Serv-u File Server,,,0.016380000859498978,false,,false,false,false,,,false,false,,2004-12-31T05:00:00.000Z,0 CVE-2004-2532,https://securityvulnerability.io/vulnerability/CVE-2004-2532,,"Serv-U FTP server before 5.1.0.0 has a default account and password for local administration, which allows local users to execute arbitrary commands by connecting to the server using the default administrator account, creating a new user, logging in as that new user, and then using the SITE EXEC command.",Solarwinds,Serv-u File Server,,,0.003530000103637576,false,,false,false,false,,,false,false,,2004-12-31T05:00:00.000Z,0 CVE-2004-0330,https://securityvulnerability.io/vulnerability/CVE-2004-0330,,Buffer overflow in Serv-U ftp before 5.0.0.4 allows remote authenticated users to execute arbitrary code via a long time zone argument to the MDTM command.,Solarwinds,Serv-u File Server,,,0.8704299926757812,false,,false,false,false,,,false,false,,2004-11-23T05:00:00.000Z,0 CVE-2004-1675,https://securityvulnerability.io/vulnerability/CVE-2004-1675,,"Serv-U FTP server 4.x and 5.x allows remote attackers to cause a denial of service (application crash) via a STORE UNIQUE (STOU) command with an MS-DOS device name argument such as (1) COM1, (2) LPT1, (3) PRN, or (4) AUX.",Solarwinds,Serv-u File Server,,,0.014709999784827232,false,,false,false,false,,,false,false,,2004-09-11T04:00:00.000Z,0 CVE-2004-1992,https://securityvulnerability.io/vulnerability/CVE-2004-1992,,"Buffer overflow in Serv-U FTP server before 5.0.0.6 allows remote attackers to cause a denial of service (crash) via a long -l parameter, which triggers an out-of-bounds read.",Solarwinds,Serv-u File Server,,,0.5650100111961365,false,,false,false,false,,,false,false,,2004-04-20T04:00:00.000Z,0 CVE-2002-2393,https://securityvulnerability.io/vulnerability/CVE-2002-2393,,"Serv-U FTP server 3.0, 3.1 and 4.0.0.4 does not accept new connections while validating user folder access rights, which allows remote attackers to cause a denial of service (no new connections) via a series of MKD commands.",Solarwinds,Serv-u File Server,,,0.012919999659061432,false,,false,false,false,,,false,false,,2002-12-31T05:00:00.000Z,0 CVE-2001-1463,https://securityvulnerability.io/vulnerability/CVE-2001-1463,,"The remote administration client for RhinoSoft Serv-U 3.0 sends the user password in plaintext even when S/KEY One-Time Password (OTP) authentication is enabled, which allows remote attackers to sniff passwords.",Solarwinds,Serv-u File Server,,,0.034359999001026154,false,,false,false,false,,,false,false,,2001-11-19T05:00:00.000Z,0 CVE-2001-0054,https://securityvulnerability.io/vulnerability/CVE-2001-0054,,"Directory traversal vulnerability in FTP Serv-U before 2.5i allows remote attackers to escape the FTP root and read arbitrary files by appending a string such as ""/..%20."" to a CD command, a variant of a .. (dot dot) attack.",Solarwinds,Serv-u File Server,,,0.011060000397264957,false,,false,false,false,,,false,false,,2001-02-16T05:00:00.000Z,0