5

CVE-2008-5692

Ipswitch WS_FTP Server Manager before 6.1.1, and possibly other Ipswitch products, allows remote attackers to bypass authentication and read logs via a logLogout action to FTPLogServer/login.asp followed by a request to FTPLogServer/LogViewer.asp with the localhostnull account name.

Data is provided by the National Vulnerability Database (NVD)
IpswitchWs Ftp Version <= 6.1
IpswitchWs Ftp Version1.0.5
IpswitchWs Ftp Version2.01
IpswitchWs Ftp Version2.02
IpswitchWs Ftp Version2.03
IpswitchWs Ftp Version3.0
IpswitchWs Ftp Version3.0.1
IpswitchWs Ftp Version3.1.0
IpswitchWs Ftp Version3.1.1
IpswitchWs Ftp Version3.1.2
IpswitchWs Ftp Version3.1.3
IpswitchWs Ftp Version3.14
IpswitchWs Ftp Version4.00
IpswitchWs Ftp Version4.01
IpswitchWs Ftp Version4.02
IpswitchWs Ftp Version5.00
IpswitchWs Ftp Version5.01
IpswitchWs Ftp Version5.02
IpswitchWs Ftp Version5.03
IpswitchWs Ftp Version5.04
IpswitchWs Ftp Version5.05
IpswitchWs Ftp Version6.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.25% 0.774
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.