Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/dievus/cve-2022-27665
Vulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration Testing
GitHubdievus/cve-2022-27665

CVE-2022-27665

Reflected XSS via AngularJS Sandbox Escape Expressions in IPSwitch WS_FTP Server 8.6.0

View Repository
13 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2022-27665

A Reflected XSS via AngularJS Sandbox Escape Expressions vulnerability exists in Progress/IPSwitch WS_FTP Server 8.6.0 that can lead to execution of malicious code and commands on the client due to improper handling of user provided input. By inputting malicious payloads in the subdirectory searchbar or Add folder filename boxes, it is possible to execute client-side commands.

This vulnerability is also known as a Client-Side Template Injection, and is similar to Server-Side Template Injections.

Vulnerability Timeline

DateAction
3/22/2022Vulnerability discovered
3/22/2022Vulnerability disclosed to vendor
3/22/2022CVE ID Requested via MITRE
3/22/2022Vendor requested resubmission via HackerOne
3/23/2022MITRE reserved CVE ID
3/23/2022HackerOne accepted submission
3/30/2022Vulnerability acknowledged by vendor and set to triaged by H1
4/03/2023Vulnerability disclosed and CVE made public

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-27665

Download Tool