#VU18943 OS Command Injection in FileZilla
Published: June 29, 2019
FileZilla
FileZilla
Description
The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.
The vulnerability exists due to insufficient validation of filenames that contain double-quotation marks when opening or editing files. A remote unauthenticated attacker that controls a remote server can trick the victim to connect to a malicious server to open a file with a specially crafted filename and execute arbitrary OS commands on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.