CVE-2018-11544
CRITICALThe Olive Tree Ftp Server 1.32 - Insufficiently Protected Credentials in Shared Preferences
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-11544. PoCs published by ManhNho.
AI-analyzed exploit summary This exploit demonstrates an insecure data storage vulnerability in Ftp Server 1.32 for Android, where credentials are stored in plaintext within a shared preferences XML file. The PoC provides a sample of the exposed configuration file containing username and password.
Description
The Olive Tree Ftp Server application 1.32 for Android has Insecure Data Storage because a username and password are stored in the /data/data/com.theolivetree.ftpserver/shared_prefs/com.theolivetree.ftpserver_preferences.xml file as the prefUsername and prefUserpass strings.
Exploits (1)
This exploit demonstrates an insecure data storage vulnerability in Ftp Server 1.32 for Android, where credentials are stored in plaintext within a shared preferences XML file. The PoC provides a sample of the exposed configuration file containing username and password.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H