10
CVSSv2

CVE-2002-2417

Published: 31/12/2002 Updated: 05/09/2008
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

acFTP 1.4 does not properly handle when an invalid password is provided by the user during authentication, which allows remote malicious users to hide or misrepresent certain activity from log files and possibly gain privileges.

Vulnerable Product Search on Vulmon Subscribe to Product

acftp acftp 1.4

Exploits

source: wwwsecurityfocuscom/bid/6235/info A vulnerability has been reported for acFTP Reportedly, acFTP allows users to authenticate without a valid password An attacker can exploit this vulnerability and log on to the vulnerable FTP server without need for proper authentication USER private PASS # ...