The default configuration of DataWizard FtpXQ 2.0 and 2.1 includes a default username and password, which allows remote attackers to read and write arbitrary files in the root folder.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/3716 | vdb entry |
http://www.securityfocus.com/archive/1/246285 | mailing list vendor advisory |
http://www.iss.net/security_center/static/7715.php | vdb entry patch vendor advisory |