7.2
CVSSv2

CVE-2005-1092

Published: 02/05/2005 Updated: 05/09/2008
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Lightspeed DeluxeFTP 6.01 stores usernames and passwords in plaintext in sites.xml, which is world-readable, which allows local users to gain privileges.

Vulnerable Product Search on Vulmon Subscribe to Product

light speed technology deluxeftp 7.0.1 beta

light speed technology deluxeftp 6.0.1

Exploits

/******************************************************************* DeluxeFtp 6x Local Password Disclosure Exploit by Kozan Application: DeluxeFtp 6x (and probably prior versions) Vendor: wwwdeluxeftpcom Vulnerable Description: DeluxeFtp 6x discloses passwords to local users Bug Discovered by: Lostmon Exploit Coded by: Kozan Credits to AT ...