CVE-2000-0038

CVSS 2.0 Score 7.5 of 10 (high)

Details

Published Dec 23, 1999
Updated: Nov 20, 2024

Summary

CVE-2000-0038 is a vulnerability affecting the glFtpD software, which comes with a default user account named "glftpd" and a password, both set to "anonymous". This account has a UID of 0, granting it administrative privileges, making it a significant security risk if the default credentials are not changed upon installation. An attacker may exploit this vulnerability to gain unauthorized access to the system and potentially cause damage or steal sensitive data. It is strongly recommended that users of glFtpD update their software and change their default credentials to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share