7.5

CVE-2005-2314

Exploit
inc.login.php in PHPsFTPd 0.2 through 0.4 allows remote attackers to obtain the administrator's username and password by setting the do_login parameter and performing an edit action using user.php, which causes the login check to be bypassed and leaks the password in the response.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
PhpsftpdPhpsftpd Version0.2
PhpsftpdPhpsftpd Version0.4
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.92% 0.772
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://cert.uni-stuttgart.de/archive/bugtraq/2005/07/msg00209.html
http://packetstorm.linuxsecurity.com/0507-exploits/phpsftpd.txt
Vendor Advisory
Exploit
http://secunia.com/advisories/15879
Vendor Advisory
http://securitytracker.com/id?1014481
http://www.securityfocus.com/bid/14222
Patch
Exploit
http://www.vupen.com/english/advisories/2005/1101