5

CVE-2008-5692

Ipswitch WS_FTP Server Manager before 6.1.1, and possibly other Ipswitch products, allows remote attackers to bypass authentication and read logs via a logLogout action to FTPLogServer/login.asp followed by a request to FTPLogServer/LogViewer.asp with the localhostnull account name.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IpswitchWs Ftp Version <= 6.1
IpswitchWs Ftp Version1.0.5
IpswitchWs Ftp Version2.01
IpswitchWs Ftp Version2.02
IpswitchWs Ftp Version2.03
IpswitchWs Ftp Version3.0
IpswitchWs Ftp Version3.0.1
IpswitchWs Ftp Version3.1.0
IpswitchWs Ftp Version3.1.1
IpswitchWs Ftp Version3.1.2
IpswitchWs Ftp Version3.1.3
IpswitchWs Ftp Version3.14
IpswitchWs Ftp Version4.00
IpswitchWs Ftp Version4.01
IpswitchWs Ftp Version4.02
IpswitchWs Ftp Version5.00
IpswitchWs Ftp Version5.01
IpswitchWs Ftp Version5.02
IpswitchWs Ftp Version5.03
IpswitchWs Ftp Version5.04
IpswitchWs Ftp Version5.05
IpswitchWs Ftp Version6.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.16% 0.779
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.