Explore Vulnerabilities SQL Injection Cross-Site Scripting (XSS) Buffer Overflow Denial of Service Remote Code Execution Remote File Include Directory Traversal HTML Injection Stack Overflow Authentication Bypass
by: Abdualhadi khalifa vendor: CrushFTP Show More CrushFTP Directory Traversal The CrushFTP server version below 10.7.1 and 11.1.0, including legacy 9.x, is vulnerable to directory traversal. An attacker can exploit this vulnerability to access sensitive files on the server by manipulating the file path in the URL. 7.1 CVSS HIGH Directory Traversal 22 CWE Product Name CrushFTP Platforms Tested Windows 10 Affected Version From: Below 10.7.1 To: 36536 2024