FlashFXP FTP Password Disclosure Vulnerability
BID:6032
Info
FlashFXP FTP Password Disclosure Vulnerability
| Bugtraq ID: | 6032 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 22 2002 12:00AM |
| Updated: | Oct 22 2002 12:00AM |
| Credit: | Discovery of this issue is credited to "Blud Clot" <[email protected]>. |
| Vulnerable: |
FlashFXP FlashFXP 1.4 |
| Not Vulnerable: |
FlashFXP FlashFXP 2.0 |
Discussion
FlashFXP FTP Password Disclosure Vulnerability
FlashFXP is prone to a vulnerability which may cause FTP authentication credentials to be disclosed to local attackers.
FTP passwords will be revealed to local attackers who edit transfer queue properties.
This may allow local attackers to gain unauthorized access for FTP sites that other local users have access to.
FlashFXP is prone to a vulnerability which may cause FTP authentication credentials to be disclosed to local attackers.
FTP passwords will be revealed to local attackers who edit transfer queue properties.
This may allow local attackers to gain unauthorized access for FTP sites that other local users have access to.
Exploit / POC
FlashFXP FTP Password Disclosure Vulnerability
There is no exploit code required.
There is no exploit code required.
Solution / Fix
FlashFXP FTP Password Disclosure Vulnerability
Solution:
This issue has been addressed in FlashFXP 2.0. Users should contact the vendor for details on obtaining an upgrade.
Solution:
This issue has been addressed in FlashFXP 2.0. Users should contact the vendor for details on obtaining an upgrade.