Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

EFTP Clear Text Password Storage Vulnerability

Encrypted FTP (EFTP) is both an FTP client and server application for Windows platforms.

EFTP stores all usernames and passwords in the file \Program Files\eftp2\eftp2users.dat in clear text. If a malicious user were to gain access to this file, they would have a list of all usernames and their associated passwords.







 

Privacy Statement
Copyright 2008, SecurityFocus