VulnerabilityModified
CVE-2006-4003
The config method in Henrik Storner Hobbit monitor before 4.1.2p2 permits access to files outside of the intended configuration directory, which allows remote attackers to obtain sensitive information via requests to the hobbitd daemon on port 1984/tcp.
MEDIUM 5.0EPSS 1.53%
Does this matter?
Lower severity and a low EPSS score (1.53%). Track it; it rarely justifies an emergency change on its own.
Description
The config method in Henrik Storner Hobbit monitor before 4.1.2p2 permits access to files outside of the intended configuration directory, which allows remote attackers to obtain sensitive information via requests to the hobbitd daemon on port 1984/tcp.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.53% probability · 73th percentile
- CISA KEV
- Not listed
- Affected
- hobbit monitor/hobbit monitor
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/21317Patch, Vendor Advisory
- http://sourceforge.net/project/shownotes.php?release_id=436594&group_id=128058Patch
- http://www.securityfocus.com/archive/1/442036/100/0/threaded
- http://www.securityfocus.com/bid/19317Patch
- http://www.vupen.com/english/advisories/2006/3139
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28204
- http://secunia.com/advisories/21317Patch, Vendor Advisory
- http://sourceforge.net/project/shownotes.php?release_id=436594&group_id=128058Patch
- http://www.securityfocus.com/archive/1/442036/100/0/threaded
- http://www.securityfocus.com/bid/19317Patch
- http://www.vupen.com/english/advisories/2006/3139
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28204
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.