Vulnerabilities > Ipswitch > WS FTP > 2.02

DATE CVE VULNERABILITY TITLE RISK
2008-12-19 CVE-2008-5693 Improper Input Validation vulnerability in Ipswitch WS FTP
Ipswitch WS_FTP Server Manager 6.1.0.0 and earlier, and possibly other Ipswitch products, might allow remote attackers to read the contents of custom ASP files in WSFTPSVR/ via a request with an appended dot character.
network
low complexity
ipswitch CWE-20
5.0
2008-12-19 CVE-2008-5692 Improper Authentication vulnerability in Ipswitch WS FTP
Ipswitch WS_FTP Server Manager before 6.1.1, and possibly other Ipswitch products, allows remote attackers to bypass authentication and read logs via a logLogout action to FTPLogServer/login.asp followed by a request to FTPLogServer/LogViewer.asp with the localhostnull account name.
network
low complexity
ipswitch CWE-287
5.0