← Vulnerability feed

Vulnerability record · CVE-2008-5693 · published 19 December 2008

CVE-2008-5693: Ipswitch ws ftp improper input validation vulnerability

Ipswitch · Ws Ftp

Ipswitch WS_FTP Server Manager 6.1.0.0 and earlier, and possibly other Ipswitch products, might allow remote attackers to read the contents of custom ASP files in WSFTPSVR/ via a request with an appended dot character.

5.0 CVSS 2.0 Medium EPSS 4.5% · top 8.8% CWE-20 · Improper input validation
5.0CVSS 2.0 base score
4.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References
16 Jun 2026Last modified by NVD

Description

Ipswitch WS_FTP Server Manager 6.1.0.0 and earlier, and possibly other Ipswitch products, might allow remote attackers to read the contents of custom ASP files in WSFTPSVR/ via a request with an appended dot character.

AV:N/AC:L/Au:N/C:P/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2008-5693 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2017-16513Ipswitch ws ftp memory buffer overflow vulnerabilityIpswitch WS_FTP Professional before 12.6.0.3 has buffer overflows in the local search field and the backup locations field, aka WSCLT-1729.EPSS 2.2%7.8CVE-2007-3823Ipswitch ws ftp vulnerabilityThe Logging Server (Logsrv.exe) in IPSwitch WS_FTP 7.5.29.0 allows remote attackers to cause a denial of service (daemon crash) by sending a crafted …EPSS 25%7.8CVE-2007-2213Ipswitch ws ftp vulnerabilityUnspecified vulnerability in the Initialize function in NetscapeFTPHandler in WS_FTP Home and Professional 2007 allows remote attackers to cause a de…EPSS 4.6%5.0CVE-2008-5692Ipswitch ws ftp improper authentication vulnerabilityIpswitch WS_FTP Server Manager before 6.1.1, and possibly other Ipswitch products, allows remote attackers to bypass authentication and read logs via…EPSS 13%5.0CVE-2008-0608Ipswitch ws ftp memory buffer overflow vulnerabilityThe Logging Server (ftplogsrv.exe) 7.9.14.0 and earlier in IPSwitch WS_FTP 6.1 allows remote attackers to cause a denial of service (loss of responsi…EPSS 5.6%4.3CVE-2009-4775Ipswitch ws ftp vulnerabilityFormat string vulnerability in Ipswitch WS_FTP Professional 12 before 12.2 allows remote attackers to cause a denial of service (crash) via format st…EPSS 5.6%4.3CVE-2007-4555Ipswitch ws ftp cross-site scripting vulnerabilityCross-site scripting (XSS) vulnerability in Ipswitch WS_FTP allows remote attackers to inject arbitrary web script or HTML via arguments to a valid c…EPSS 1.6%9.5CVE-2026-93952Arista velocloud orchestrator improper input validation vulnerabilityVeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality an…KEVEPSS 0.90%

Source: NIST National Vulnerability Database (record CVE-2008-5693), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.