Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

gFTP On-Screen Plaintext Password Vulnerability

gFTP is a freely available graphical file transfer client for UNIX based machines running X11R6 or later. It includes support for file transfers using the FTP, HTTP, and SSH protocols.

When a user logs on to an FTP server using gFTP the login password is displayed in plaintext on the screen.

The effect is that anyone viewing the screen during a login will be privy to the password.







 

Privacy Statement
Copyright 2009, SecurityFocus