← Back

Pyftpd

pyftpd

Vendor: Debian • 1 CVE

CVEs (1)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Debian
1Pyftpd
Apr 29, 2026
Jun 16, 2010
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
auth_db_config.py in Pyftpd 0.8.4 contains hard-coded usernames and passwords for the (1) test, (2) user, and (3) roxon accounts, which allows remote attackers to read arbitrary files from the FTP server.