VulnerabilityModified
CVE-2005-0746
The Mini FTP server in Novell iChain 2.2 and 2.3 SP2 and earlier allows remote unauthenticated attackers to obtain the full path of the server via the PWD command.
MEDIUM 5.0EPSS 1.81%
Does this matter?
Lower severity and a low EPSS score (1.81%). Track it; it rarely justifies an emergency change on its own.
Description
The Mini FTP server in Novell iChain 2.2 and 2.3 SP2 and earlier allows remote unauthenticated attackers to obtain the full path of the server via the PWD command.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.81% probability · 77th percentile
- CISA KEV
- Not listed
- Affected
- novell/ichain
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=111091102023359&w=2
- http://secunia.com/advisories/14537
- http://securitytracker.com/id?1013407
- http://support.novell.com/cgi-bin/search/searchtid.cgi?/10096886.htm
- http://www.infobyte.com.ar/adv/ISR-03.html
- http://www.securityfocus.com/bid/12766
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19643
- http://marc.info/?l=bugtraq&m=111091102023359&w=2
- http://secunia.com/advisories/14537
- http://securitytracker.com/id?1013407
- http://support.novell.com/cgi-bin/search/searchtid.cgi?/10096886.htm
- http://www.infobyte.com.ar/adv/ISR-03.html
- http://www.securityfocus.com/bid/12766
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19643
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.