PT-2002-2660 · Flashfxp · Flashfxp
Published
2002-12-31
·
Updated
2008-09-05
·
CVE-2002-1939
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
FlashFXP version 1.4
Description
The issue allows attackers to obtain FTP passwords of other users by editing the queue properties when there are transfers in the queue, as FlashFXP prints FTP passwords in plaintext.
Recommendations
For FlashFXP version 1.4, consider restricting access to the queue properties to minimize the risk of exploitation until a fix is available. As a temporary workaround, avoid editing queue properties when there are transfers in the queue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Flashfxp