PT-2005-1781 · Novell · Mini Ftp Server+1
Francisco Amato
·
Published
2005-03-13
·
Updated
2017-07-11
·
CVE-2005-0746
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Novell iChain versions 2.2 through 2.3 SP2
Description
The issue allows remote unauthenticated attackers to obtain the full path of the server. This is achieved via the PWD command in the Mini FTP server.
Recommendations
For Novell iChain versions 2.2 through 2.3 SP2, consider restricting access to the Mini FTP server until a fix is available. As a temporary workaround, disabling the PWD command in the Mini FTP server may help minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mini Ftp Server
Novell Ichain