Unrated severityNVD Advisory· Published May 2, 2005· Updated Apr 16, 2026
CVE-2005-1092
CVE-2005-1092
Description
Lightspeed DeluxeFTP 6.01 stores usernames and passwords in plaintext in sites.xml, which is world-readable, which allows local users to gain privileges.
Affected products
2cpe:2.3:a:light_speed_technology:deluxeftp:6.0.1:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:light_speed_technology:deluxeftp:6.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:light_speed_technology:deluxeftp:7.0.1_beta:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- lostmon.blogspot.com/2005/04/deluxeftp-plain-text-passwords.htmlnvdExploitVendor Advisory
- secunia.com/advisories/14923nvdVendor Advisory
- www.osvdb.org/15421nvd
- www.securityfocus.com/bid/13105nvd
News mentions
0No linked articles in our index yet.