Description
Wing FTP Server versions prior to 6.2.7 contain a cross-site request forgery (CSRF) vulnerability in the web administration interface that allows attackers to delete admin users. Attackers can craft a malicious HTML page with a hidden form to submit a request that deletes the administrative user account without proper authorization.
Problem types
Cross-Site Request Forgery (CSRF)
Product status
Credits
Dhiraj Mishra
References
www.exploit-db.com/exploits/48200 (ExploitDB-48200)
www.wftpserver.com (Wing FTP Server Official Homepage)
www.wftpserver.com/serverhistory.htm (Wing FTP Server Version History)
www.vulncheck.com/...g-ftp-server-cross-site-request-forgery (VulnCheck Advisory: Wing FTP Server < 6.2.7 - Cross-site Request Forgery)