PT-2002-2660 · Flashfxp · Flashfxp

Published

2002-12-31

·

Updated

2008-09-05

·

CVE-2002-1939

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions FlashFXP version 1.4
Description The issue allows attackers to obtain FTP passwords of other users by editing the queue properties when there are transfers in the queue, as FlashFXP prints FTP passwords in plaintext.
Recommendations For FlashFXP version 1.4, consider restricting access to the queue properties to minimize the risk of exploitation until a fix is available. As a temporary workaround, avoid editing queue properties when there are transfers in the queue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-1939

Affected Products

Flashfxp