CVE-2008-5692
MEDIUM 5.0EPSS 12.6%
Ipswitch WS_FTP Server Manager before 6.1.1, and possibly other Ipswitch products, allows remote attackers to bypass authentication and read logs via a logLogout action to FTPLogServer/login.asp followed by a request to FTPLogServer/LogViewer.asp with the localhostnull account name.
- CVSS v2.0
- 5.0 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N - EPSS
- 12.65% chance of exploitation in the next 30 days, 96th percentile
- Published
- 2008-12-19
- Updated
- 2024-08-07