SonicALERT
Search

Sonicwall Signatures

 

Go to All Categories list.


  CrushFTP AS2 Authentication Bypass

Category: WEB-ATTACKS      

CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote attackers to obtain admin access via HTTPS.


Relevant Information