The Serv-U File Server allows for events such as user login failures to be audited by executing a command. This command can be supplied with parameters that can take the form of user string variables, allowing remote code execution.
2021-08-31T16:15:07.750
2024-11-21T06:12:05.767
Modified
CVSSv3.1: 8.5 (HIGH)
AV:N/AC:L/Au:S/C:P/I:P/A:P
8.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | solarwinds | serv-u | < 15.2.4 | Yes |