Back to search
CVE-2002-2417
Published: Nov 1, 2007
Modified: Aug 8, 2024
PUBLISHED
Description
acFTP 1.4 does not properly handle when an invalid password is provided by the user during authentication, which allows remote attackers to hide or misrepresent certain activity from log files and possibly gain privileges.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
6235
vdb-entry
x_refsource_BID
3334
third-party-advisory
x_refsource_SREASON
acftp-authentication-bypass(10681)
vdb-entry
x_refsource_XF
20021123 acFTP Authentication Issue
mailing-list
x_refsource_VULNWATCH
20021124 acFTP Authentication Issue
mailing-list
x_refsource_BUGTRAQ
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now