Lucene search

K
exploitdbAndreas FinstadEDB-ID:51268
HistoryApr 06, 2023 - 12:00 a.m.

TitanFTP 2.0.1.2102 - Path traversal to Remote Code Execution (RCE)

2023-04-0600:00:00
Andreas Finstad
www.exploit-db.com
131
titanftp
path traversal
remote code execution
windows server 2022
cve-2023-22629

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

9.1 High

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

74.0%

# Exploit Title: TitanFTP 2.0.1.2102 - Path traversal to Remote Code Execution (RCE)

# Date: 02.14.2023
# Exploit Author: Andreas Finstad
# Vendor Homepage: https://titanftp.com/

# Version: < 2.0.1.2102

# Tested on: Windows 2022 Server
# CVE : CVE-2023-22629


Exploit and description here:
https://f20.be/blog/titanftp

Kind regards
Andreas Finstad

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

9.1 High

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

74.0%