Weak access control permissions in MELAG FTP Server 2.2.0.4 allow the "Everyone" group to read the local FTP configuration file, which includes among other information the unencrypted passwords of all FTP users.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://www.securesystems.de/blog/advisory-and-exploitation-the-melag-ftp-server/ | third party advisory exploit |