FTPGlide Insecure Local Profile Storage Vulnerability
BID:10815
Info
FTPGlide Insecure Local Profile Storage Vulnerability
| Bugtraq ID: | 10815 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 27 2004 12:00AM |
| Updated: | Jul 27 2004 12:00AM |
| Credit: | Discovery of this vulnerability is credited to Ziv Kamir. |
| Vulnerable: |
FTPGlide FTPGlide 2.0 |
| Not Vulnerable: | |
Discussion
FTPGlide Insecure Local Profile Storage Vulnerability
FTPGlide is reported prone to an insecure profile storage vulnerability. FTPGlide provides functionality where a user can save an FTP or HTTP site profile; this profile contains the server address, the username and may contain the password if the option to save the password is selected.
Any user who has access to the installation directory will have access to all saved profiles.
FTPGlide is reported prone to an insecure profile storage vulnerability. FTPGlide provides functionality where a user can save an FTP or HTTP site profile; this profile contains the server address, the username and may contain the password if the option to save the password is selected.
Any user who has access to the installation directory will have access to all saved profiles.
Exploit / POC
FTPGlide Insecure Local Profile Storage Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
FTPGlide Insecure Local Profile Storage Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.