CVE-2010-2428

Wftpserver Wing FTP Server < 3.5.0 - XSS

Title source: rule

Description

Cross-site scripting (XSS) vulnerability in admin_loginok.html in the Administrator web interface in Wing FTP Server for Windows 3.5.0 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted POST request.

Scores

EPSS 0.0075
EPSS Percentile 72.8%

Classification

CWE
CWE-79
Status published

Affected Products (26)

wftpserver/wing_ftp_server < 3.5.0
wftpserver/wing_ftp_server
wftpserver/wing_ftp_server
wftpserver/wing_ftp_server
wftpserver/wing_ftp_server
wftpserver/wing_ftp_server
wftpserver/wing_ftp_server
wftpserver/wing_ftp_server
wftpserver/wing_ftp_server
wftpserver/wing_ftp_server
wftpserver/wing_ftp_server
wftpserver/wing_ftp_server
wftpserver/wing_ftp_server
wftpserver/wing_ftp_server
wftpserver/wing_ftp_server
... and 11 more

Timeline

Published Jun 24, 2010
Tracked Since Feb 18, 2026