CVE-2025-47812 - Wing FTP Server Remote Code Execution (RCE)
by thermos - Monday July 28, 2025 at 02:54 PM
#11
(Jul 28, 2025, 02:54 PM)thermos Wrote: This vulnerability originates from Wing FTP Server's improper handling of NULL bytes within the username parameter during the authentication process. This allows attackers to inject Lua code directly into session files. These malicious session files are then executed when a valid session is loaded, leading to arbitrary command execution on the server.

Key features of this exploit include:

Remote Code Execution: Execute any command you choose on the target server.
Root/SYSTEM Privileges: Often achieves RCE with the highest system privileges due to the default configurations of Wing FTP Server.
Anonymous Access Exploitation: Can be leveraged even if only anonymous logins are permitted on the server.
Batch Scanning: Scan multiple targets by providing a list of URLs from a file.
Custom Command Execution: Specify and run any command you need on the vulnerable server.
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  Google Dorks for finding SQL injection vulnerabilities and other security issues 1yush 64 2,742 Apr 24, 2026, 05:17 AM
Last Post: p2wnz_bontensec
  CVE-2024-32002 RCE PoC HA_twck 1 370 Apr 24, 2026, 05:13 AM
Last Post: p2wnz_bontensec
  GeoServer: Full Exploit + Mass Scanning Utility Loki 26 2,753 Apr 24, 2026, 04:56 AM
Last Post: p2wnz_bontensec
  New Zer0 Day Wordpress A3g00n 78 2,764 Apr 24, 2026, 04:54 AM
Last Post: p2wnz_bontensec
  {SECRET} DATABASE OF EXPLOITS lulagain 428 24,395 Apr 24, 2026, 04:53 AM
Last Post: p2wnz_bontensec

Forum Jump:


 Users browsing this forum: 1 Guest(s)