PT-2005-4801 · Ghisler · Total Commander
Publicado
2005-12-07
·
Atualizado
2017-07-20
·
CVE-2005-4066
CVSS v2.0
4.9
Média
| Vetor | AV:L/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Total Commander version 6.53
Description
The issue concerns the use of weak encryption in storing FTP usernames and passwords in the WCX FTP.INI file, allowing local users to decrypt the passwords and gain unauthorized access to FTP servers.
Recommendations
For version 6.53, consider updating the storage mechanism for FTP credentials to use stronger encryption methods to protect against unauthorized access. As a temporary workaround, restrict access to the WCX FTP.INI file to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Total Commander