PT-2023-24251 · Wftpd · Wftpd
CVE-2023-33263
·
Publicado
2023-05-25
·
Atualizado
2025-01-16
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
WFTPD version 3.25
Description
The software stores usernames and password hashes in an openly viewable wftpd.ini configuration file within the WFTPD directory. This issue is noted in a product from 2006.
Recommendations
For WFTPD version 3.25, consider restricting access to the wftpd.ini configuration file to minimize the risk of exploitation. As a temporary workaround, limit read access to this file until a more secure storage method for usernames and password hashes is implemented.
Correção
Insufficiently Protected Credentials
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Wftpd