Application: WingFTP Server 3.2.4 (maybe earlier versions too) Link: http://www.wftpserver.com/ Vulnerability: CSRF Author: Ams Contact: mail: ax330d [at] gmail [dot] com site: http://www.0x416d73.name/ 1. About software "Wing FTP server is not only a FTP server. It's a multi-protocol file server(FTP, HTTP, FTPS, HTTPS, SFTP) for Windows, Linux, Mac, freeBSD and Solaris. It includes a new set of advanced tools (web based remote control, web based client, administrator console, task scheduler). It provides event manager for the program to respond to different events, scripts support let users extend the server by Lua language, virtual directories for easy sharing files and directories, and more ... " 2. Vulnerability details Wing FTP server web based administration panel provides option to view logs. We can watch logs by opening [Domains -> your.domain -> Logs & Status -> Domain Log (or Activity)] These logs are opened directly from file to ajax'ed tag