VulnerabilityModified
CVE-2006-6949
Conti FTPServer 1.0 Build 2.8 stores user passwords in cleartext in MyServerSettings.ini, which allows local users to obtain sensitive information by reading this file.
MEDIUM 4.6EPSS 0.32%
Does this matter?
Lower severity and a low EPSS score (0.32%). Track it; it rarely justifies an emergency change on its own.
Description
Conti FTPServer 1.0 Build 2.8 stores user passwords in cleartext in MyServerSettings.ini, which allows local users to obtain sensitive information by reading this file.
- CVSS 2.0
- 4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 0.32% probability · 25th percentile
- CISA KEV
- Not listed
- Affected
- conti/ftpserver
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/23030Vendor Advisory
- http://secwatch.org/advisories/1016194/Vendor Advisory
- http://www.securityfocus.com/bid/21174Vendor Advisory
- http://www.vupen.com/english/advisories/2006/4605
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30412
- http://secunia.com/advisories/23030Vendor Advisory
- http://secwatch.org/advisories/1016194/Vendor Advisory
- http://www.securityfocus.com/bid/21174Vendor Advisory
- http://www.vupen.com/english/advisories/2006/4605
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30412
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.