mirror of
https://github.com/0xMarcio/cve.git
synced 2026-02-12 18:42:46 +00:00
18 lines
728 B
Markdown
18 lines
728 B
Markdown
### [CVE-2021-41635](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-41635)
|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
When installed as Windows service MELAG FTP Server 2.2.0.4 is run as SYSTEM user, which grants remote attackers to abuse misconfigurations or vulnerabilities with administrative access over the entire host system.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
- https://www.securesystems.de/blog/advisory-and-exploitation-the-melag-ftp-server/
|
|
|
|
#### Github
|
|
No PoCs found on GitHub currently.
|
|
|