CVE-2008-5692: Medium severity Ipswitch WS FTP Server vulnerability
Ipswitch WSFTP Server Manager before 6.1.1, and possibly other Ipswitch products, allows remote attackers to bypass authentication and read logs via a logLogout action to FTPLogServer/login.asp followed by a request to FTPLogServer/LogViewer.asp with the localhostnull account name.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-5692?
CVE-2008-5692 has been classified with a high severity score due to its capability to allow remote attackers to bypass authentication.
How do I fix CVE-2008-5692?
To fix CVE-2008-5692, upgrade the Ipswitch WS_FTP Server Manager to version 6.1.1 or later.
What products are affected by CVE-2008-5692?
CVE-2008-5692 affects various versions of Ipswitch WS_FTP, specifically versions prior to 6.1.1.
Can CVE-2008-5692 allow access to sensitive logs?
Yes, CVE-2008-5692 allows attackers to read logs due to the authentication bypass vulnerability.
What is the exploit method for CVE-2008-5692?
Attackers exploit CVE-2008-5692 by sending a logLogout action followed by a request to access LogViewer.asp.