cve/2017/CVE-2017-15272.md
2024-06-18 02:51:15 +02:00

853 B

CVE-2017-15272

Description

The PSFTPd 10.0.4 Build 729 server stores its configuration inside PSFTPd.dat. This file is a Microsoft Access Database and can be extracted. The application sets the encrypt flag with the password "ITsILLEGAL"; however, this password is not required to extract the data. Cleartext is used for a user password.

POC

Reference

Github

No PoCs found on GitHub currently.