Vulnerability Description
FlashFXP 1.4 prints FTP passwords in plaintext when there are transfers in the queue, which allows attackers to obtain FTP passwords of other users by editing the queue properties.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Flashfxp | Flashfxp | 1.4 |
References
- http://online.securityfocus.com/archive/1/296658
- http://www.iss.net/security_center/static/10445.phpPatch
- http://www.securityfocus.com/bid/6032
- http://online.securityfocus.com/archive/1/296658
- http://www.iss.net/security_center/static/10445.phpPatch
- http://www.securityfocus.com/bid/6032
FAQ
What is CVE-2002-1939?
CVE-2002-1939 is a vulnerability with a CVSS score of 2.1 (LOW). FlashFXP 1.4 prints FTP passwords in plaintext when there are transfers in the queue, which allows attackers to obtain FTP passwords of other users by editing the queue properties.
How severe is CVE-2002-1939?
CVE-2002-1939 has been rated LOW with a CVSS base score of 2.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2002-1939?
Check the references section above for vendor advisories and patch information. Affected products include: Flashfxp Flashfxp.