Power Server FTP Addon Plaintext Password Storage Weakness
BID:7984
Info
Power Server FTP Addon Plaintext Password Storage Weakness
| Bugtraq ID: | 7984 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 19 2003 12:00AM |
| Updated: | Jun 19 2003 12:00AM |
| Credit: | This vulnerability was reported by Ziv Kamir <[email protected]>. |
| Vulnerable: |
Power Server Power Server 1.0 |
| Not Vulnerable: | |
Discussion
Power Server FTP Addon Plaintext Password Storage Weakness
Power Server FTP Addon stores usernames and associated passwords using plaintext format, in the 'FTPUsers' directory. As a result, these credentials could be exposed to other local users who have the permissions to access and read that file.
Power Server FTP Addon stores usernames and associated passwords using plaintext format, in the 'FTPUsers' directory. As a result, these credentials could be exposed to other local users who have the permissions to access and read that file.
References
Power Server FTP Addon Plaintext Password Storage Weakness
References:
References:
- Power Server Product Page (Power Server)