CVE-2015-10003
4.3
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Exploitability: 2.8 / Impact: 1.4
Source: NVD
Description
A vulnerability, which was classified as problematic, was found in FileZilla Server up to 0.9.50. This affects an unknown part of the component PORT Handler. The manipulation leads to unintended intermediary. It is possible to initiate the attack remotely. Upgrading to version 0.9.51 is able to address this issue. It is recommended to upgrade the affected component.
Affected (1)
Products: Filezilla Project: Filezilla Server
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 0.9.51 |
Related CWEs
CWE-441
Unintended Proxy or Intermediary ('Confused Deputy')
The product receives a request, message, or directive from an upstream component, but the product does not sufficiently preserve the original source of the request before forwarding the request to an external actor that is outside of the product's control sphere. This causes the product to appear to be the source of the request, leading it to act as a proxy or other intermediary between the upstream component and the external actor.
CWE-610
Externally Controlled Reference to a Resource in Another Sphere
The product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere.
References (4)
Source: cna@vuldb.com
PatchTechnical DescriptionThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchTechnical DescriptionThird Party Advisory
Timeline
No history available yet.