Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2017-15272

The PSFTPd 10.0.4 Build 729 server stores its configuration inside PSFTPd.dat. This file is a Microsoft Access Database and can be extracted. The application sets the encrypt flag with the password "ITsILLEGAL"; however, this password is not required to extract the data. Cleartext is used for a user password.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 20.4%
CVSS Severity
CVSS v3 Score 5.3
CVSS v2 Score 2.1
Products affected by CVE-2017-15272
  • Psftp » Psftpd » Version: 10.0.4
    cpe:2.3:a:psftp:psftpd:10.0.4


Contact Us

Shodan ® - All rights reserved