VulnerabilityModified
CVE-2001-0768
GuildFTPd 0.9.7 stores user names and passwords in plaintext in the default.usr file, which allows local users to gain privileges as other FTP users by reading the file.
MEDIUM 4.6EPSS 0.33%
Does this matter?
Lower severity and a low EPSS score (0.33%). Track it; it rarely justifies an emergency change on its own.
Description
GuildFTPd 0.9.7 stores user names and passwords in plaintext in the default.usr file, which allows local users to gain privileges as other FTP users by reading the file.
- CVSS 2.0
- 4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 0.33% probability · 26th percentile
- CISA KEV
- Not listed
- Affected
- steve poulsen/guildftpd
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/bugtraq/2001-05/0250.htmlVendor Advisory
- http://www.securityfocus.com/bid/2792Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6611
- http://archives.neohapsis.com/archives/bugtraq/2001-05/0250.htmlVendor Advisory
- http://www.securityfocus.com/bid/2792Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6611
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.