CVE-2019-16116 EXPLOIT
4.3
MEDIUM · CVSS 3.1 · EPSS 3.7% (pctl 89)
Patch early
A public exploit exists.
Description
EnterpriseDT CompleteFTP Server prior to version 12.1.3 is vulnerable to information exposure in the Bootstrap.log file. This allows an attacker to obtain the administrator password hash.
Scoring
| CVSS | 4.3 (MEDIUM, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
| EPSS | 3.68% — more likely to be exploited than 89% of all CVEs |
| Weakness | CWE-327 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2019-10-02 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| enterprisedt | completeftp server |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | CompleteFTP Professional 12.1.3 - Remote Code Execution | 2020-07-09 |
References
- https://enterprisedt.com/products/completeftp/doc/guide/html/history.html
- https://rhinosecuritylabs.com/application-security/completeftp-server-local-privesc-cve-2019-16116/
- https://enterprisedt.com/products/completeftp/doc/guide/html/history.html
- https://rhinosecuritylabs.com/application-security/completeftp-server-local-privesc-cve-2019-16116/
→ the Explorer · watch your stack · NVD