VulnerabilityModified
CVE-2004-1948
NcFTP client 3.1.6 and 3.1.7, when the username and password are included in an FTP URL that is provided on the command line, allows local users to obtain sensitive information via "ps aux," which displays the URL in the process list.
MEDIUM 4.6EPSS 0.46%
Does this matter?
Lower severity and a low EPSS score (0.46%). Track it; it rarely justifies an emergency change on its own.
Description
NcFTP client 3.1.6 and 3.1.7, when the username and password are included in an FTP URL that is provided on the command line, allows local users to obtain sensitive information via "ps aux," which displays the URL in the process list.
- CVSS 2.0
- 4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 0.46% probability · 39th percentile
- CISA KEV
- Not listed
- Affected
- ncftp software/ncftp
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=108247943201685&w=2
- http://secunia.com/advisories/11438Exploit, Vendor Advisory
- http://www.osvdb.org/5595
- http://www.securityfocus.com/bid/10182Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15919
- http://marc.info/?l=bugtraq&m=108247943201685&w=2
- http://secunia.com/advisories/11438Exploit, Vendor Advisory
- http://www.osvdb.org/5595
- http://www.securityfocus.com/bid/10182Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15919
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.