Cerberus FTP Server Plaintext User Password Weakness
BID:7556
Info
Cerberus FTP Server Plaintext User Password Weakness
| Bugtraq ID: | 7556 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | May 12 2003 12:00AM |
| Updated: | May 12 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to "Ziv Kamir" <[email protected]>. |
| Vulnerable: |
Cerberus FTP Server 2.1 |
| Not Vulnerable: | |
Discussion
Cerberus FTP Server Plaintext User Password Weakness
Cerberus FTP Server stores authentication credentials for the FTP service on the local system in plaintext. Local users with access to the file used to store these credentials may gain unauthorized access to the server as a result.
Cerberus FTP Server stores authentication credentials for the FTP service on the local system in plaintext. Local users with access to the file used to store these credentials may gain unauthorized access to the server as a result.
Exploit / POC
Cerberus FTP Server Plaintext User Password Weakness
There is no exploit required.
There is no exploit required.
Solution / Fix
Cerberus FTP Server Plaintext User Password Weakness
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.