vendor:
FlashFXP
by:
Dvdman@l33tsecurity.com
2.6
CVSS
LOW
Trivially reversible algorithm to encrypt FTP user credentials
N/A
CWE
Product Name: FlashFXP
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2003
FlashFXP sites.dat decryption
FlashFXP uses a trivially reversible algorithm to encrypt FTP user credentials. Local attackers with access to the sites.data may exploit this weakness to gain unauthorized access to FTP user credentials for remote sites.
Mitigation:
Ensure that the sites.data file is not accessible to unauthorized users.