PT-2005-3241 · Php · Phpsftpd
Published
2005-07-19
·
Updated
2011-03-08
·
CVE-2005-2314
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
PHPsFTPd versions 0.2 through 0.4
Description:
The issue allows remote attackers to obtain the administrator's username and password. This is achieved by setting the
do login parameter and performing an edit action using user.php, which bypasses the login check and leaks the password in the response.Recommendations:
For PHPsFTPd versions 0.2 through 0.4, consider restricting access to the
user.php endpoint and the do login parameter until a patch is available. As a temporary workaround, avoid using the do login parameter in the affected endpoint to minimize the risk of exploitation.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Phpsftpd