← Vulnerability feed

Vulnerability record · CVE-2007-4555 · published 28 August 2007

CVE-2007-4555: Ipswitch ws ftp cross-site scripting vulnerability

Ipswitch · Ws Ftp

Cross-site scripting (XSS) vulnerability in Ipswitch WS_FTP allows remote attackers to inject arbitrary web script or HTML via arguments to a valid command, which is not properly handled when it is displayed by the view log option in the administration interface. NOTE: this can be leveraged to create a new admin account.

4.3 CVSS 2.0 Medium EPSS 1.6% · top 24.7% CWE-79 · Cross-site scripting
4.3CVSS 2.0 base score
1.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References
16 Jun 2026Last modified by NVD

Description

Cross-site scripting (XSS) vulnerability in Ipswitch WS_FTP allows remote attackers to inject arbitrary web script or HTML via arguments to a valid command, which is not properly handled when it is displayed by the view log option in the administration interface. NOTE: this can be leveraged to create a new admin account.

AV:N/AC:M/Au:N/C:N/I:P/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2007-4555 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2017-16513Ipswitch ws ftp memory buffer overflow vulnerabilityIpswitch WS_FTP Professional before 12.6.0.3 has buffer overflows in the local search field and the backup locations field, aka WSCLT-1729.EPSS 2.2%7.8CVE-2007-3823Ipswitch ws ftp vulnerabilityThe Logging Server (Logsrv.exe) in IPSwitch WS_FTP 7.5.29.0 allows remote attackers to cause a denial of service (daemon crash) by sending a crafted …EPSS 25%7.8CVE-2007-2213Ipswitch ws ftp vulnerabilityUnspecified vulnerability in the Initialize function in NetscapeFTPHandler in WS_FTP Home and Professional 2007 allows remote attackers to cause a de…EPSS 4.6%5.0CVE-2008-5692Ipswitch ws ftp improper authentication vulnerabilityIpswitch WS_FTP Server Manager before 6.1.1, and possibly other Ipswitch products, allows remote attackers to bypass authentication and read logs via…EPSS 13%5.0CVE-2008-5693Ipswitch ws ftp improper input validation vulnerabilityIpswitch WS_FTP Server Manager 6.1.0.0 and earlier, and possibly other Ipswitch products, might allow remote attackers to read the contents of custom…EPSS 4.5%5.0CVE-2008-0608Ipswitch ws ftp memory buffer overflow vulnerabilityThe Logging Server (ftplogsrv.exe) 7.9.14.0 and earlier in IPSwitch WS_FTP 6.1 allows remote attackers to cause a denial of service (loss of responsi…EPSS 5.6%4.3CVE-2009-4775Ipswitch ws ftp vulnerabilityFormat string vulnerability in Ipswitch WS_FTP Professional 12 before 12.2 allows remote attackers to cause a denial of service (crash) via format st…EPSS 5.6%6.1CVE-2026-42897Microsoft Exchange Server XSS enables spoofingMicrosoft Exchange Server and Exchange Server Subscription Edition fail to neutralize input during web page generation, a cross-site scripting flaw (…KEVEPSS 0.52%analysed

Source: NIST National Vulnerability Database (record CVE-2007-4555), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.