Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
NetWin SurgeFTP 2.0f and earlier encrypts passwords using weak hashing, a fixed salt value and modulo 40 calculations, which allows remote attackers to conduct brute force password guessing attacks against the administrator account on port 7021.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
SurgeFTP 脆弱密码加密漏洞
Vulnerability Description
CVE(CAN) ID: CAN-2001-1356 SurgeFTP是新西兰NetWin公司的一款基于多平台的的FTP服务器。 由于SurgFTP的密码使用脆弱的散列算法加密,并且使用单一固定的salt,导致攻击者 可以快速对管理员密码进行穷举破解,而且用一个密码密文可能对应多个不同的密码明 文。
CVSS Information
N/A
Vulnerability Type
N/A