GuildFTPD Plaintext Password Storage Vulnerability

GuildFTPD is a free Windows-based ftp server by DrPhibez and Nitro187.

GuildFTPD's user credentials are stored in plain text in a document residing in the program's directory. Users may gain access to the file through the use of a trivial directory traversal bug (BID #2789).


 

Privacy Statement
Copyright 2010, SecurityFocus