Vulnerabilities > CVE-2005-1092 - Local Authentication Credentials Disclosure vulnerability in Light Speed Technologies DeluxeFTP

047910
CVSS 7.2 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
local
low complexity
light-speed-technology
exploit available

Summary

Lightspeed DeluxeFTP 6.01 stores usernames and passwords in plaintext in sites.xml, which is world-readable, which allows local users to gain privileges.

Exploit-Db

descriptionDeluxeFtp 6.x Local Password Disclosure Exploit. CVE-2005-1092. Local exploit for windows platform
idEDB-ID:936
last seen2016-01-31
modified2005-04-13
published2005-04-13
reporterKozan
sourcehttps://www.exploit-db.com/download/936/
titleDeluxeFtp 6.x - Local Password Disclosure Exploit