acFTP Invalid Password Weak Authentication Vulnerability
BID:6235
Info
acFTP Invalid Password Weak Authentication Vulnerability
| Bugtraq ID: | 6235 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 25 2002 12:00AM |
| Updated: | Nov 25 2002 12:00AM |
| Credit: | Discovery of this vulnerability credited to "Matthew Murphy" <[email protected]>. |
| Vulnerable: |
acFTP acFTP 1.4 |
| Not Vulnerable: | |
Discussion
acFTP Invalid Password Weak Authentication Vulnerability
A vulnerability has been reported for acFTP. Reportedly, acFTP allows users to authenticate without a valid password.
An attacker can exploit this vulnerability and log on to the vulnerable FTP server without need for proper authentication.
A vulnerability has been reported for acFTP. Reportedly, acFTP allows users to authenticate without a valid password.
An attacker can exploit this vulnerability and log on to the vulnerable FTP server without need for proper authentication.
References
acFTP Invalid Password Weak Authentication Vulnerability
References:
References:
- acFTP (acFTP)
- acFTP Authentication Issue ("Matthew Murphy"
)