
Cloud Vulnerability DB
A community-led vulnerabilities database
EnterpriseDT CompleteFTP Server versions prior to 12.1.3 contained a vulnerability that exposed sensitive information in the Bootstrap.log file, allowing attackers to obtain the administrator password hash. The vulnerability was discovered in September 2019 and was assigned CVE-2019-16116 (CVE Details, Rhino Labs).
The vulnerability stems from information leakage in the Bootstrap.log file located in the Server subdirectory of the program installation directory. The log file, created during initial installation, contained SQL statements with the administrator's MD5 password hash and an encrypted passphrase used for authentication. This information could be used to gain unauthorized access to the CompleteFTP Manager interface with full administrative privileges (Rhino Labs). The vulnerability has a CVSS v3.1 base score of 4.3 (MEDIUM) with vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N (NVD).
The vulnerability allows attackers with read access to the program installation directory to obtain administrative credentials and gain full control of the CompleteFTP Server. Since the server runs by default with SYSTEM privileges, attackers could leverage built-in Process Triggers functionality to execute arbitrary code and escalate privileges on the Windows system (Rhino Labs).
The vulnerability is exploitable both locally and potentially remotely if a user is granted read access to the program installation directory. An attacker only needs access to the CompleteFTPManager.exe binary and the information leaked in the Bootstrap.log file to gain administrative access. A proof-of-concept exploit has been published demonstrating the complete attack chain (Rhino Labs).
The vulnerability was patched in CompleteFTP Server version 12.1.3. Users should upgrade to this version or later to mitigate the risk. All versions 12.1.2 and below are considered vulnerable (Rhino Labs).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."