Pablo Software Solutions FTP Service Plaintext Password Weakness
BID:7801
Info
Pablo Software Solutions FTP Service Plaintext Password Weakness
| Bugtraq ID: | 7801 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 03 2003 12:00AM |
| Updated: | Jun 03 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to JeiAr <[email protected]>. |
| Vulnerable: |
Pablo Software Solutions FTP Service 1.2 |
| Not Vulnerable: | |
Discussion
Pablo Software Solutions FTP Service Plaintext Password Weakness
It has been reported that Pablo FTP Service stores FTP User account passwords in plaintext format. As a result, these credentials could be exposed to other users.
This issue may be further exaggerated by BID 7799.
It should be noted that while this weakness has been reported to affect Pablo FTP service version 1.2, other versions might also be affected.
It has been reported that Pablo FTP Service stores FTP User account passwords in plaintext format. As a result, these credentials could be exposed to other users.
This issue may be further exaggerated by BID 7799.
It should be noted that while this weakness has been reported to affect Pablo FTP service version 1.2, other versions might also be affected.
Exploit / POC
Pablo Software Solutions FTP Service Plaintext Password Weakness
The following proof of concept has been provided:
ftp://www.example.com/program files/pablo's ftp service/users.dat
The following proof of concept has been provided:
ftp://www.example.com/program files/pablo's ftp service/users.dat
Solution / Fix
Pablo Software Solutions FTP Service Plaintext Password Weakness
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Pablo Software Solutions FTP Service Plaintext Password Weakness
References:
References:
- FTP Service Homepage (Pablo Software Solutions)
- Vulnerabilities In Pablo Software Solutions FTP Service 1.2 (JeiAr
)