Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

InstantServers MiniPortal Sensitive File Plain Text Storage Vulnerability

InstantServers MiniPortal is a web server package for Windows based machines, based on the Apache project web server. It includes a web based administrative interface, and a bundled FTP server.

MiniPortal stores user's authentication and user account information in the file ftpusers.pwd. Login and session information is stored in miniportal.txt or mplog.txt. Due to a design flaw both files are stored in plain text.







 

Privacy Statement
Copyright 2008, SecurityFocus