Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

Wing FTP Server Local Path Disclosure Vulnerability

Vulnerability

A local path disclosure vulnerability has been identified in Wing FTP Server versions prior to 7.4.4. The issue arises in the 'loginok.html' file, where the application inadvertently reveals the full local installation path when a long value is used in the UID cookie. This vulnerability can be exploited by manipulating the UID cookie to include excessive data, causing the server to respond with the sensitive path information.

Impact

Exploitation of this vulnerability leads to unauthorized disclosure of the application's local installation path, which could be leveraged for further attacks or exploitation.

Reproduction

To reproduce this vulnerability, send a request to the Wing FTP Server web interface with a UID cookie that contains a long value. The server will respond with the 'loginok.html' file, disclosing the full local installation path of the application. This can be done using a web browser or a tool that allows for cookie manipulation, such as a browser extension or a script that modifies cookie values.

Remediation

Users are advised to update to Wing FTP Server version 7.4.4 or later, where this vulnerability has been fixed.

Added: Jul 10, 2025, 5:54 PM
Updated: Mar 16, 2026, 5:04 PM

Vulnerability Rating

Custom Algorithm
spread
1.9
impact
0.0
exploitability
9.8
remediation
7.7
relevance
0.2
threat
8.5
urgency
2.9
incentive
10.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.