Description
EnterpriseDT CompleteFTP Server prior to version 12.1.3 is vulnerable to information exposure in the Bootstrap.log file. This allows an attacker to obtain the administrator password hash.
References
https://enterprisedt.com/products/completeftp/doc/guide/html/history.html
Release NotesVendor Advisory
https://rhinosecuritylabs.com/application-security/completeftp-server-local-privesc-cve-2019-16116/
ExploitThird Party Advisory
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
4.3 · Medium
CVSS V3.1
CVSS V3.0
CVSS V2.0
Information
Source identifier
Vulnerability status
Analyzed
Published
2019-10-02T16:15:14.287
5 years agoLast modified
2021-07-21T11:39:23.747
3 years ago