cgi/surgeftpmgr.cgi (aka the Web Manager interface on TCP port 7021 or 9021) in NetWin SurgeFTP version 23f2 has XSS via the classid, domainid, or username parameter.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2017-12-29T18:00:00

Updated: 2017-12-29T17:57:01

Reserved: 2017-12-27T00:00:00


Link: CVE-2017-17933

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2017-12-29T18:29:00.507

Modified: 2021-09-10T02:44:18.480


Link: CVE-2017-17933

JSON object: View

cve-icon Redhat Information

No data.

CWE