PT-2005-4801 · Ghisler · Total Commander
Published
2005-12-07
·
Updated
2017-07-20
·
CVE-2005-4066
CVSS v2.0
4.9
Medium
| Vector | AV:L/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Total Commander version 6.53
Description
The issue concerns the use of weak encryption in storing FTP usernames and passwords in the WCX FTP.INI file, allowing local users to decrypt the passwords and gain unauthorized access to FTP servers.
Recommendations
For version 6.53, consider updating the storage mechanism for FTP credentials to use stronger encryption methods to protect against unauthorized access. As a temporary workaround, restrict access to the WCX FTP.INI file to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Total Commander