FTP Credentials Disclosure

medium Web App Scanning Plugin ID 113080

Synopsis

FTP Credentials Disclosure

Description

The web server on the remote host contains publicly accessible FTP configuration files. These configuration files are produced by ftp software and contain details of ftp credentials and/or hosts and other potentially sensitive information. This may be used to access content from the FTP server that might otherwise be private.

Solution

Remove the listed FTP configuration files.

See Also

https://codexns.io/products/sftp_for_sublime/settings

https://filezillapro.com/docs/v3/advanced/how-to-configure-filezilla-pro-defaults-file-fzdefaults-xml/

Plugin Details

Severity: Medium

ID: 113080

Type: remote

Published: 12/21/2021

Updated: 1/17/2023

Scan Template: api, basic, full, pci, scan

Risk Information

VPR

Risk Factor: Low

Score: 1.4

CVSS v2

Risk Factor: Medium

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS Score Source: Tenable

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CVSS Score Source: Tenable

CVSS v4

Risk Factor: Medium

Base Score: 6.9

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

CVSS Score Source: Tenable

Reference Information