CVE-2005-4066

Total Commander 6.53 uses weak encryption to store FTP usernames and passwords in WCX_FTP.INI, which allows local users to decrypt the passwords and gain access to FTP servers, as possibly demonstrated by the W32.Gudeb worm.
Configurations

Configuration 1 (hide)

cpe:2.3:a:christian_ghisler:total_commander:6.53:*:*:*:*:*:*:*

History

21 Nov 2024, 00:03

Type Values Removed Values Added
References () http://securitytracker.com/id?1015311 - Vendor Advisory () http://securitytracker.com/id?1015311 - Vendor Advisory
References () http://www.networksecurity.fi/advisories/total-commander.html - Vendor Advisory () http://www.networksecurity.fi/advisories/total-commander.html - Vendor Advisory
References () http://www.vupen.com/english/advisories/2005/2780 - Vendor Advisory () http://www.vupen.com/english/advisories/2005/2780 - Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/23497 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/23497 -

Information

Published : 2005-12-07 11:03

Updated : 2024-11-21 00:03


NVD link : CVE-2005-4066

Mitre link : CVE-2005-4066

CVE.ORG link : CVE-2005-4066


JSON object : View

Products Affected

christian_ghisler

  • total_commander
CWE
CWE-310

Cryptographic Issues