PT-2010-3684 · Pyftpd · Pyftpd
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Pyftpd version 0.8.4
Description
The issue concerns hard-coded usernames and passwords in the auth db config.py file for the test, user, and roxon accounts. This allows remote attackers to read arbitrary files from the FTP server.
Recommendations
For Pyftpd version 0.8.4, consider removing or modifying the hard-coded usernames and passwords in the auth db config.py file to prevent unauthorized access. As a temporary workaround, restrict access to the FTP server until the issue is resolved.
Correção
Using Hardcoded Credentials
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Pyftpd