vendor:
Wing FTP Server
by:
v1n1v131r4
7.5
CVSS
HIGH
Remote Code Execution
78
CWE
Product Name: Wing FTP Server
Affected Version From: 6.3.8
Affected Version To: 6.3.8
Patch Exists: YES
Related CWE: N/A
CPE: a:wftpserver:wing_ftp_server
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10
2020
Wing FTP Server 6.3.8 – Remote Code Execution (Authenticated)
Wing FTP Server have a web console based on Lua language. For authenticated users, this console can be exploited to obtaining a reverse shell. Generate a payload using msfvenom and send and execute it via POST.
Mitigation:
Ensure that the web console is not accessible to unauthorized users and that the server is running the latest version of the software.