CVE-2008-5124
CVE-2008-5124
JSCAPE Secure FTP Applet 4.8.0 and earlier does not ask the user to verify a new or mismatched SSH host key, which makes it easier for remote attackers to perform man-in-the-middle attacks.
Produtos afetados
n/a · n/aQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
http://secunia.com/advisories/30822http://securityreason.com/securityalert/4606https://exchange.xforce.ibmcloud.com/vulnerabilities/43300http://www.jscape.com/sftpapplet/docs/HTML/index.html?introhistory.htmlhttp://www.securityfocus.com/archive/1/493569/100/0/threadedhttp://www.securityfocus.com/archive/1/493652/100/0/threadedhttp://www.securityfocus.com/bid/29882http://www.securitytracker.com/id?1020346http://www.vupen.com/english/advisories/2008/1919/references