PT-2001-2460 · Cesarftp · Cesarftp
Published
2001-05-28
·
Updated
2008-09-10
·
CVE-2001-1336
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
CesarFTP versions 0.98b and earlier
Description
The issue allows attackers to gain privileges by accessing usernames and passwords stored in plaintext in the settings.ini file.
Recommendations
For CesarFTP versions 0.98b and earlier, consider encrypting or securely storing sensitive information such as usernames and passwords to prevent unauthorized access. As a temporary workaround, restrict access to the settings.ini file to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cesarftp