20040808 Serv-U 3.x, 4.x, 5.x local privilege escalation vulnerabilitymailing list
http://archives.neohapsis.com/archives/fulldisclosure/2004-08/0216.html CVE-2004-2532
RhinoSoft Serv-U FTP Server 3.x < 5.x - Local Privilege Escalation
Record summary
CVE-2004-2532 has a selected CVSS score of 10.0; EIP currently links 1 catalogued exploit.
Description
Serv-U FTP server before 5.1.0.0 has a default account and password for local administration, which allows local users to execute arbitrary commands by connecting to the server using the default administrator account, creating a new user, logging in as that new user, and then using the SITE EXEC command.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBRhinoSoft Serv-U FTP Server 3.x < 5.x - Local Privilege EscalationExploitDB exploitby Andrés AcunhaNot analyzed1 file
References
58877vdb entry
http://www.osvdb.org/8877 10886vdb entry
http://www.securityfocus.com/bid/10886 servu-default-admin-account(16925)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/16925 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2004-2532