peter bassill · operator
$ cve CVE-2019-16116 JSON

CVE-2019-16116 EXPLOIT

4.3
MEDIUM · CVSS 3.1 · EPSS 3.7% (pctl 89)

Patch early

A public exploit exists.

Description

EnterpriseDT CompleteFTP Server prior to version 12.1.3 is vulnerable to information exposure in the Bootstrap.log file. This allows an attacker to obtain the administrator password hash.

Scoring

CVSS4.3 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS3.68% — more likely to be exploited than 89% of all CVEs
WeaknessCWE-327
On CISA KEVno
Public exploityes
Published2019-10-02
Last modified2026-06-17

Affected (1)

VendorProduct
enterprisedtcompleteftp server

Public exploits

SourceTitleDate
exploit-dbCompleteFTP Professional 12.1.3 - Remote Code Execution2020-07-09

References

→ the Explorer  ·  watch your stack  ·  NVD