Efssoft's vulnerability footprint centers on a narrow line of file-sharing and transfer products, including Easy File Sharing Web Server and Easy File Sharing FTP Server, with the durable signal concentrated on web application and file-handling input validation issues such as cross-site scripting, path traversal, and buffer-boundary violations. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Efssoft over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-3791HIGH Stack-based buffer overflow in Easy File Sharing (EFS) Web Server 6.8 allows remote attackers to execute arbitrary code via a long string in a cookie UserID parameter to vfolder.gh | May 20, 2014 | 10.0 | 83 | NO | YES |
CVE-2017-6510HIGH Easy File Sharing FTP Server version 3.6 is vulnerable to a directory traversal vulnerability which allows an attacker to list and download any file from any folder outside the FTP | Mar 16, 2017 | 7.5 | 43 | NO | YES |
CVE-2014-9439MEDIUM Cross-site scripting (XSS) vulnerability in Easy File Sharing Web Server 6.8 allows remote attackers to inject arbitrary web script or HTML via the username field during registrati | Jan 2, 2015 | 4.3 | 26 | NO | YES |
CVE-2014-5178MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Easy File Sharing (EFS) Web Server 6.8 allow remote authenticated users to inject arbitrary web script or HTML via the conten | Aug 6, 2014 | 4.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Efssoft.
Media articles that mention a CVE ID that affects a product developed by Efssoft — matched by CVE ID, not by vendor name.