PT-2020-20244 · Wing · Wing Ftp Server
Published
2020-03-06
·
Updated
2020-03-09
·
CVE-2020-8634
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Wing FTP Server version 6.2.3
Description
The issue allows files modified within the HTTP file management interface to be saved with world-readable and world-writable permissions. This could potentially enable a low-privilege user to escalate privileges to root if a sensitive system file were edited in this manner.
Recommendations
For Wing FTP Server version 6.2.3, consider restricting access to sensitive system files and modifying the permissions manually after editing to prevent world-readable and world-writable access until a fix is available.
Exploit
Fix
Improper Preservation of Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wing Ftp Server