GuildFTPD Plaintext Password Storage Vulnerability
BID:2792
Info
GuildFTPD Plaintext Password Storage Vulnerability
| Bugtraq ID: | 2792 |
| Class: | Design Error |
| CVE: |
CVE-2001-0768 |
| Remote: | Yes |
| Local: | No |
| Published: | May 26 2001 12:00AM |
| Updated: | Jul 11 2009 06:06AM |
| Credit: | Discovered and posted to Bugtraq by ByteRage <[email protected]> on May 26, 2001. |
| Vulnerable: |
DrPhibez and Nitro187 Guild FTPD 0.9.7 |
| Not Vulnerable: | |
Discussion
GuildFTPD Plaintext Password Storage Vulnerability
GuildFTPD is a free Windows-based ftp server by DrPhibez and Nitro187.
GuildFTPD's user credentials are stored in plain text in a document residing in the program's directory. Users may gain access to the file through the use of a trivial directory traversal bug (BID #2789).
GuildFTPD is a free Windows-based ftp server by DrPhibez and Nitro187.
GuildFTPD's user credentials are stored in plain text in a document residing in the program's directory. Users may gain access to the file through the use of a trivial directory traversal bug (BID #2789).
Exploit / POC
GuildFTPD Plaintext Password Storage Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
GuildFTPD Plaintext Password Storage Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
GuildFTPD Plaintext Password Storage Vulnerability
References:
References:
- Guild FTPD Homepage (Dr.Phibez and Nitro187)
- GuildFTPD Directory Traversal Vulnerability (SecurityFocus)