CVE-2018-11544

CRITICAL

Theolivetree FTP Server - Insufficiently Protected Credentials

Title source: rule

Description

The Olive Tree Ftp Server application 1.32 for Android has Insecure Data Storage because a username and password are stored in the /data/data/com.theolivetree.ftpserver/shared_prefs/com.theolivetree.ftpserver_preferences.xml file as the prefUsername and prefUserpass strings.

Exploits (1)

exploitdb WORKING POC
by ManhNho · textlocalandroid
https://www.exploit-db.com/exploits/44852

Scores

CVSS v3 9.8
EPSS 0.0031
EPSS Percentile 54.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-522
Status published
Products (1)
theolivetree/ftp_server 1.32
Published May 29, 2018
Tracked Since Feb 18, 2026