loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a long value in the UID cookie.
Attack Parameters
Impact Assessment
CVSS Vector v3.1
Weakness Type (CWE)
Vulnerable Products 1
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Wftpserver Wing_Ftp_Server
cpe:2.3:a:wftpserver:wing_ftp_server:*:*:*:*:*:*:*:*
|
— |
7.4.4
|