PT-2005-1781 · Novell · Mini Ftp Server+1
Francisco Amato
·
Publicado
2005-03-13
·
Atualizado
2017-07-11
·
CVE-2005-0746
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Novell iChain versions 2.2 through 2.3 SP2
Description
The issue allows remote unauthenticated attackers to obtain the full path of the server. This is achieved via the PWD command in the Mini FTP server.
Recommendations
For Novell iChain versions 2.2 through 2.3 SP2, consider restricting access to the Mini FTP server until a fix is available. As a temporary workaround, disabling the PWD command in the Mini FTP server may help minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Mini Ftp Server
Novell Ichain