CVE-2019-16116

EnterpriseDT CompleteFTP Server prior to version 12.1.3 is vulnerable to information exposure in the Bootstrap.log file. This allows an attacker to obtain the administrator password hash.
Configurations

Configuration 1 (hide)

cpe:2.3:a:enterprisedt:completeftp_server:*:*:*:*:*:*:*:*

History

21 Nov 2024, 04:30

Type Values Removed Values Added
References () https://enterprisedt.com/products/completeftp/doc/guide/html/history.html - Release Notes, Vendor Advisory () https://enterprisedt.com/products/completeftp/doc/guide/html/history.html - Release Notes, Vendor Advisory
References () https://rhinosecuritylabs.com/application-security/completeftp-server-local-privesc-cve-2019-16116/ - Exploit, Third Party Advisory () https://rhinosecuritylabs.com/application-security/completeftp-server-local-privesc-cve-2019-16116/ - Exploit, Third Party Advisory

Information

Published : 2019-10-02 16:15

Updated : 2024-11-21 04:30


NVD link : CVE-2019-16116

Mitre link : CVE-2019-16116

CVE.ORG link : CVE-2019-16116


JSON object : View

Products Affected

enterprisedt

  • completeftp_server
CWE
CWE-327

Use of a Broken or Risky Cryptographic Algorithm

CWE-532

Insertion of Sensitive Information into Log File