PT-2002-1334 · Powerftp · Powerftp Personal Ftp Server

Publicado

2002-05-03

·

Atualizado

2016-10-18

·

CVE-2002-0264

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PowerFTP Personal FTP Server versions 2.03 through 2.10
Description The issue concerns the storage of sensitive account information in plaintext within the ftpserver.ini file. This allows attackers who gain access to the file to obtain privileges.
Recommendations For PowerFTP Personal FTP Server versions 2.03 through 2.10, consider restricting access to the ftpserver.ini file to minimize the risk of exploitation. Additionally, avoid storing sensitive account information in plaintext to reduce the potential impact of this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-0264

Produtos afetados

Powerftp Personal Ftp Server