CVE-2008-5693: Input Validation
Published Dec 19, 2008
·Updated
Ipswitch WSFTP Server Manager 6.1.0.0 and earlier, and possibly other Ipswitch products, might allow remote attackers to read the contents of custom ASP files in WSFTPSVR/ via a request with an appended dot character.
Affected Software
22 affected components
Ipswitch WS FTP Server=3.1.1
Ipswitch WS FTP Server=2.01
Ipswitch WS FTP Server<=6.1
Ipswitch WS FTP Server=3.1.0
Ipswitch WS FTP Server=5.00
Ipswitch WS FTP Server=5.03
Ipswitch WS FTP Server=3.1.3
Ipswitch WS FTP Server=2.02
Ipswitch WS FTP Server=4.01
Ipswitch WS FTP Server=6.0
Ipswitch WS FTP Server=2.03
Ipswitch WS FTP Server=3.0
Ipswitch WS FTP Server=5.02
Ipswitch WS FTP Server=1.0.5
Ipswitch WS FTP Server=4.00
Ipswitch WS FTP Server=5.05
Ipswitch WS FTP Server=5.01
Ipswitch WS FTP Server=5.04
Ipswitch WS FTP Server=3.0.1
Ipswitch WS FTP Server=3.14
Ipswitch WS FTP Server=4.02
Ipswitch WS FTP Server=3.1.2
Event History
Dec 19, 2008
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Data Sourced
via NVD·06:30 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2008-5693?
CVE-2008-5693 is considered to have a medium severity level.
2
How do I fix CVE-2008-5693?
To rectify CVE-2008-5693, it is recommended to upgrade to a version of Ipswitch WS_FTP that is later than 6.1.0.0.
3
What products are affected by CVE-2008-5693?
CVE-2008-5693 affects Ipswitch WS_FTP Server Manager versions up to and including 6.1.0.0.
4
What attack vector does CVE-2008-5693 utilize?
CVE-2008-5693 allows remote attackers to read the contents of custom ASP files by appending a dot character to the request.
5
Can CVE-2008-5693 lead to data exposure?
Yes, CVE-2008-5693 can lead to unauthorized access and potential data exposure of sensitive ASP files.