Vulnerability Description
The Mini FTP server in Novell iChain 2.2 and 2.3 SP2 and earlier allows remote unauthenticated attackers to obtain the full path of the server via the PWD command.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Novell | Ichain | 2.2 |
References
- http://marc.info/?l=bugtraq&m=111091102023359&w=2
- http://secunia.com/advisories/14537
- http://securitytracker.com/id?1013407
- http://support.novell.com/cgi-bin/search/searchtid.cgi?/10096886.htm
- http://www.infobyte.com.ar/adv/ISR-03.html
- http://www.securityfocus.com/bid/12766
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19643
- http://marc.info/?l=bugtraq&m=111091102023359&w=2
- http://secunia.com/advisories/14537
- http://securitytracker.com/id?1013407
- http://support.novell.com/cgi-bin/search/searchtid.cgi?/10096886.htm
- http://www.infobyte.com.ar/adv/ISR-03.html
- http://www.securityfocus.com/bid/12766
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19643
FAQ
What is CVE-2005-0746?
CVE-2005-0746 is a vulnerability with a CVSS score of 5.0 (MEDIUM). The Mini FTP server in Novell iChain 2.2 and 2.3 SP2 and earlier allows remote unauthenticated attackers to obtain the full path of the server via the PWD command.
How severe is CVE-2005-0746?
CVE-2005-0746 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2005-0746?
Check the references section above for vendor advisories and patch information. Affected products include: Novell Ichain.