Vulnerability Name:

CVE-2008-5692 (CCN-40315)

Assigned:2008-02-06
Published:2008-02-06
Updated:2018-10-11
Summary:Ipswitch WS_FTP Server Manager before 6.1.1, and possibly other Ipswitch products, allows remote attackers to bypass authentication and read logs via a logLogout action to FTPLogServer/login.asp followed by a request to FTPLogServer/LogViewer.asp with the localhostnull account name.
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
4.3 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:H/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
4.3 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:H/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-287
Vulnerability Consequences:Bypass Security
References:Source: CCN
Type: Luigi Auriemma Advisories, 06 Feb 2008:
Logs visualization in WS_FTP Server Manager 6.1.0.0

Source: MISC
Type: UNKNOWN
http://aluigi.altervista.org/adv/wsftpweblog-adv.txt

Source: MITRE
Type: CNA
CVE-2008-5692

Source: CCN
Type: Ipswitch Web site
Release Notes for WS_FTP Server 6.1.1 and WS_FTP Server 6.1.1 with SSH, Fixed in 6.1.1

Source: CONFIRM
Type: UNKNOWN
http://docs.ipswitch.com/WS_FTP_Server611/ReleaseNotes/index.htm?k_id=ipswitch_ftp_documents_worldwide_ws_ftpserverv611releasenotes#link12

Source: CCN
Type: SA28822
IPSwitch WS_FTP Server Manager Security Bypass

Source: SECUNIA
Type: UNKNOWN
28822

Source: SREASON
Type: UNKNOWN
4799

Source: CCN
Type: OSVDB ID: 42046
WS_FTP Server Manager /WSFTPSVR/FTPLogServer/LogViewer.asp Authentication Bypass

Source: BUGTRAQ
Type: UNKNOWN
20080206 Logs visualization in WS_FTP Server Manager 6.1.0.0

Source: BUGTRAQ
Type: UNKNOWN
20080206 Re: Logs visualization in WS_FTP Server Manager 6.1.0.0

Source: BID
Type: UNKNOWN
27654

Source: CCN
Type: BID-27654
WS_FTP Server Manager Authentication Bypass and Information Disclosure Vulnerabilities

Source: VUPEN
Type: UNKNOWN
ADV-2008-0473

Source: CCN
Type: WS_FTP Web site
Ipswitch WS_FTP Server

Source: XF
Type: UNKNOWN
ipswitch-wsftp-login-security-bypass(40315)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:ipswitch:ws_ftp:1.0.5:*:*:*:*:*:*:*
  • OR cpe:/a:ipswitch:ws_ftp:2.01:*:*:*:*:*:*:*
  • OR cpe:/a:ipswitch:ws_ftp:2.02:*:*:*:*:*:*:*
  • OR cpe:/a:ipswitch:ws_ftp:2.03:*:*:*:*:*:*:*
  • OR cpe:/a:ipswitch:ws_ftp:3.0:*:*:*:*:*:*:*
  • OR cpe:/a:ipswitch:ws_ftp:3.0.1:*:*:*:*:*:*:*
  • OR cpe:/a:ipswitch:ws_ftp:3.1.0:*:*:*:*:*:*:*
  • OR cpe:/a:ipswitch:ws_ftp:3.1.1:*:*:*:*:*:*:*
  • OR cpe:/a:ipswitch:ws_ftp:3.1.2:*:*:*:*:*:*:*
  • OR cpe:/a:ipswitch:ws_ftp:3.1.3:*:*:*:*:*:*:*
  • OR cpe:/a:ipswitch:ws_ftp:3.14:*:*:*:*:*:*:*
  • OR cpe:/a:ipswitch:ws_ftp:4.00:*:*:*:*:*:*:*
  • OR cpe:/a:ipswitch:ws_ftp:4.01:*:*:*:*:*:*:*
  • OR cpe:/a:ipswitch:ws_ftp:4.02:*:*:*:*:*:*:*
  • OR cpe:/a:ipswitch:ws_ftp:5.00:*:*:*:*:*:*:*
  • OR cpe:/a:ipswitch:ws_ftp:5.01:*:*:*:*:*:*:*
  • OR cpe:/a:ipswitch:ws_ftp:5.02:*:*:*:*:*:*:*
  • OR cpe:/a:ipswitch:ws_ftp:5.03:*:*:*:*:*:*:*
  • OR cpe:/a:ipswitch:ws_ftp:5.04:*:*:*:*:*:*:*
  • OR cpe:/a:ipswitch:ws_ftp:5.05:*:*:*:*:*:*:*
  • OR cpe:/a:ipswitch:ws_ftp:6.0:*:*:*:*:*:*:*
  • OR cpe:/a:ipswitch:ws_ftp:*:*:*:*:*:*:*:* (Version <= 6.1)

  • * Denotes that component is vulnerable
    BACK
    ipswitch ws ftp 1.0.5
    ipswitch ws ftp 2.01
    ipswitch ws ftp 2.02
    ipswitch ws ftp 2.03
    ipswitch ws ftp 3.0
    ipswitch ws ftp 3.0.1
    ipswitch ws ftp 3.1.0
    ipswitch ws ftp 3.1.1
    ipswitch ws ftp 3.1.2
    ipswitch ws ftp 3.1.3
    ipswitch ws ftp 3.14
    ipswitch ws ftp 4.00
    ipswitch ws ftp 4.01
    ipswitch ws ftp 4.02
    ipswitch ws ftp 5.00
    ipswitch ws ftp 5.01
    ipswitch ws ftp 5.02
    ipswitch ws ftp 5.03
    ipswitch ws ftp 5.04
    ipswitch ws ftp 5.05
    ipswitch ws ftp 6.0
    ipswitch ws ftp *