← All CVEs

CVE-2008-5692

medium · 5

Ipswitch WS_FTP Server Manager before 6.1.1, and possibly other Ipswitch products, allows remote attackers to bypass authentication and read logs via a logLogout action to FTPLogServer/login.asp followed by a request to FTPLogServer/LogViewer.asp with the localhostnull account name.

5
CVSS
12.6%
EPSS (exploit prob.)
96th
EPSS percentile
2008-12-19
Published

AV:N/AC:L/Au:N/C:P/I:N/A:N

Weaknesses

CWE-287

Affected products

VendorProductAffected versions
ipswitchws_ftp<= 6.1
ipswitchws_ftp1.0.5
ipswitchws_ftp2.01
ipswitchws_ftp2.02
ipswitchws_ftp2.03
ipswitchws_ftp3.0
ipswitchws_ftp3.0.1
ipswitchws_ftp3.1.0
ipswitchws_ftp3.1.1
ipswitchws_ftp3.1.2
ipswitchws_ftp3.1.3
ipswitchws_ftp3.14
ipswitchws_ftp4.00
ipswitchws_ftp4.01
ipswitchws_ftp4.02
ipswitchws_ftp5.00
ipswitchws_ftp5.01
ipswitchws_ftp5.02
ipswitchws_ftp5.03
ipswitchws_ftp5.04
ipswitchws_ftp5.05
ipswitchws_ftp6.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2008-5692