DataWizard FtpXQ Privileged Default Account Permissions Vulnerability
BID:3716
Info
DataWizard FtpXQ Privileged Default Account Permissions Vulnerability
| Bugtraq ID: | 3716 |
| Class: | Design Error |
| CVE: |
CVE-2001-1213 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 19 2001 12:00AM |
| Updated: | Jul 11 2009 09:06AM |
| Credit: | Discovered and posted to Bugtraq by Brice Carlson <[email protected]>. |
| Vulnerable: |
DataWizard FtpXQ 2.1 DataWizard FtpXQ 2.0 |
| Not Vulnerable: | |
Discussion
DataWizard FtpXQ Privileged Default Account Permissions Vulnerability
FtpXQ is a ftp daemon designed to provide ftp services for Microsoft Operating Systems. The software package has been written for Microsoft Windows 95/98/NT/2000. It is maintained and distributed by Datawizard Technologies.
Default accounts included with FtpXQ have read and write access to the drive c:\, potentially compromising sensitive information on the server or jeopardizing the integrity of the host system.
FtpXQ is a ftp daemon designed to provide ftp services for Microsoft Operating Systems. The software package has been written for Microsoft Windows 95/98/NT/2000. It is maintained and distributed by Datawizard Technologies.
Default accounts included with FtpXQ have read and write access to the drive c:\, potentially compromising sensitive information on the server or jeopardizing the integrity of the host system.
Exploit / POC
DataWizard FtpXQ Privileged Default Account Permissions Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
DataWizard FtpXQ Privileged Default Account Permissions Vulnerability
Solution:
The vendor has acknowledged this issue and will change the default access to be read only.
Solution:
The vendor has acknowledged this issue and will change the default access to be read only.
References
DataWizard FtpXQ Privileged Default Account Permissions Vulnerability
References:
References:
- DataWizard Homepage (DataWizard)