Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2005-2898

Опубликовано: 14 сент. 2005
Источник: nvd
CVSS2: 4.6
EPSS Низкий

Описание

NOTE: this issue has been disputed by the vendor. FileZilla 2.2.14b and 2.2.15, and possibly earlier versions, when "Use secure mode" is disabled, uses a weak encryption scheme to store the user's password in the configuration settings file, which allows local users to obtain sensitive information. NOTE: the vendor has disputed the issue, stating that "the problem is not a vulnerability at all, but in fact a fundamental issue of every single program that can store passwords transparently.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:filezilla:filezilla:2.2.14b:*:*:*:*:*:*:*
cpe:2.3:a:filezilla:filezilla:2.2.15:*:*:*:*:*:*:*

EPSS

Процентиль: 42%
0.00199
Низкий

4.6 Medium

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
почти 4 года назад

** DISPUTED ** NOTE: this issue has been disputed by the vendor. FileZilla 2.2.14b and 2.2.15, and possibly earlier versions, when "Use secure mode" is disabled, uses a weak encryption scheme to store the user's password in the configuration settings file, which allows local users to obtain sensitive information. NOTE: the vendor has disputed the issue, stating that "the problem is not a vulnerability at all, but in fact a fundamental issue of every single program that can store passwords transparently."

EPSS

Процентиль: 42%
0.00199
Низкий

4.6 Medium

CVSS2

Дефекты

NVD-CWE-Other