MELAG FTP Server 2.2.0.4 stores unencrpyted passwords of FTP users in a local configuration file.
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
Link | Tags |
---|---|
https://www.securesystems.de/blog/advisory-and-exploitation-the-melag-ftp-server/ | third party advisory exploit |