VulnerabilityModified
CVE-2005-2727
Home Ftp Server 1.0.7 stores sensitive user information and server information in the same directory as the user's home directory, which allows remote authenticated users to obtain sensitive information by obtaining ftpmembers.lst and ftpsettings.lst.
MEDIUM 5.0EPSS 1.43%
Does this matter?
Lower severity and a low EPSS score (1.43%). Track it; it rarely justifies an emergency change on its own.
Description
Home Ftp Server 1.0.7 stores sensitive user information and server information in the same directory as the user's home directory, which allows remote authenticated users to obtain sensitive information by obtaining ftpmembers.lst and ftpsettings.lst.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.43% probability · 71th percentile
- CISA KEV
- Not listed
- Affected
- ari pikivirta/home ftp server
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=112490496918102&w=2
- http://www.autistici.org/fdonato/advisory/HomeFtpServer1.0.7-adv.txt
- http://www.securityfocus.com/bid/14653
- https://exchange.xforce.ibmcloud.com/vulnerabilities/22002
- http://marc.info/?l=bugtraq&m=112490496918102&w=2
- http://www.autistici.org/fdonato/advisory/HomeFtpServer1.0.7-adv.txt
- http://www.securityfocus.com/bid/14653
- https://exchange.xforce.ibmcloud.com/vulnerabilities/22002
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.