|
|
Info |
Last Modified |
| 6 months ago |
|
|
|
|
Description |
EFTP contains a flaw that may allow a local or remote attacker to gain the passwords of every FTP user. The issue is due to the program not using encryption when storing user passwords in the \Program Files\eftp2\eftp2users.dat file.
|
|
Classification |
Location:
Remote/Network Access Required
Attack Type:
Cryptographic,
Information Disclosure
Impact:
Loss of Integrity
Exploit:
Exploit Available
Disclosure:
OSVDB Verified
|
|
Solution |
Upgrade to version 3.2 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.
|
|
Products |
|
EFTP
 |
2.0.7.337 |
|
|
|
|
|
Credit |
- ByteRage - byterage
yahoo.com - Personal Page
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|