CVE-2025-47812: Wing FTP Server <= 7.4.3 - Remote Code Execution

CVE-2025-47812: Wing FTP Server <= 7.4.3 - Remote Code Execution-渗透云记 - 专注于网络安全与技术分享
CVE-2025-47812: Wing FTP Server <= 7.4.3 - Remote Code Execution
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2025-47812: Wing FTP Server <= 7.4.3 – Remote Code Execution

漏洞描述

Wing FTP Server versions prior to 7.4.4 are vulnerable to an unauthenticated remote code execution (rce) flaw (CVE-2025-47812).

The vulnerability arises from improper NULL byte handling in the 'username' parameter during login, which allows Lua code injection

into session files. These injected session files are executed when accessing authenticated endpoints such as /dir.html, resulting

in arbitrary command execution with elevated privileges. This attack is possible only when anonymous login is enabled on the server.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享