vendor:
Ftp Server
by:
ManhNho
N/A
CVSS
N/A
Credential Disclosure
CWE
Product Name: Ftp Server
Affected Version From: 1.32
Affected Version To: 1.32
Patch Exists: NO
Related CWE:
CPE: com.theolivetree.ftpserver
Platforms Tested: Android
2018
Ftp Server 1.32 – Credential Disclosure
Ftp Server 1.32 Insecure Data Storage, the result of storing confidential information insecurely on the system i.e. poor encryption, plain text, access control issues etc. Attacker can find out username/password of valid user via /data/data/com.theolivetree.ftpserver/shared_prefs/com.theolivetree.ftpserver_preferences.xml
Mitigation:
Unknown