Total vulnerabilities in the database
NetWin SurgeFTP prior to 1.1h allows a remote attacker to cause a denial of service (crash) via an 'ls ..' command.
CVSS v2:
No CWE or OWASP classifications available.