Vulnerability Name:

CVE-2005-0746 (CCN-19643)

Assigned:2005-03-09
Published:2005-03-09
Updated:2017-07-11
Summary:The Mini FTP server in Novell iChain 2.2 and 2.3 SP2 and earlier allows remote unauthenticated attackers to obtain the full path of the server via the PWD command.
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-Other
Vulnerability Consequences:Obtain Information
References:Source: MITRE
Type: CNA
CVE-2005-0746

Source: BUGTRAQ
Type: UNKNOWN
20050315 [ISR] - Novell iChain Mini FTP Server Unauthorized Remote Path Disclosure Vulnerability

Source: CCN
Type: SA14537
Novell iChain FTP Server Path Disclosure Weakness

Source: SECUNIA
Type: UNKNOWN
14537

Source: CCN
Type: SECTRACK ID: 1013407
Novell iChain Mini FTP Server Discloses Installation Path to Remote Users

Source: SECTRACK
Type: UNKNOWN
1013407

Source: CCN
Type: Novell Technical Information Document TID10096886
iChain Security concern with Mini FTP

Source: CONFIRM
Type: UNKNOWN
http://support.novell.com/cgi-bin/search/searchtid.cgi?/10096886.htm

Source: CCN
Type: TID2974706
iChain 2.3 Support Pack 4 Interim Release 2 version 2.3.320

Source: MISC
Type: UNKNOWN
http://www.infobyte.com.ar/adv/ISR-03.html

Source: CCN
Type: Novell iChain Web Site
Novell iChain: Federated Single Sign-on

Source: CCN
Type: OSVDB ID: 14620
Novell iChain Mini FTP Server PWD Command Path Disclosure

Source: BID
Type: UNKNOWN
12766

Source: CCN
Type: BID-12766
Novell iChain Mini FTP Server Unauthorized Remote Path Disclosure Vulnerability

Source: XF
Type: UNKNOWN
ichain-path-disclosure(19643)

Source: XF
Type: UNKNOWN
ichain-path-disclosure(19643)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:novell:ichain:2.2:*:*:*:*:*:*:*
  • OR cpe:/a:novell:ichain:2.2:sp1:*:*:*:*:*:*
  • OR cpe:/a:novell:ichain:2.2:sp1a:*:*:*:*:*:*
  • OR cpe:/a:novell:ichain:2.2:sp2:*:*:*:*:*:*
  • OR cpe:/a:novell:ichain:2.2:sp3:*:*:*:*:*:*
  • OR cpe:/a:novell:ichain:2.2.113:*:*:*:*:*:*:*
  • OR cpe:/a:novell:ichain:2.3:*:*:*:*:*:*:*
  • OR cpe:/a:novell:ichain:2.3:sp2:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:novell:ichain:2.2:*:*:*:*:*:*:*
  • OR cpe:/a:novell:netware:6.5:*:*:*:*:*:*:*
  • OR cpe:/a:novell:ichain:2.3:*:*:*:*:*:*:*
  • OR cpe:/a:novell:ichain:2.2:sp1:*:*:*:*:*:*
  • OR cpe:/a:novell:ichain:2.2:sp2:*:*:*:*:*:*
  • OR cpe:/a:novell:ichain:2.2:sp3:*:*:*:*:*:*
  • OR cpe:/a:novell:ichain:2.3:sp2:*:*:*:*:*:*
  • OR cpe:/a:novell:ichain:2.2.113:*:*:*:*:*:*:*
  • AND
  • cpe:/o:novell:netware:5.1:*:*:*:*:*:*:*
  • OR cpe:/o:novell:netware:6.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    novell ichain 2.2
    novell ichain 2.2 sp1
    novell ichain 2.2 sp1a
    novell ichain 2.2 sp2
    novell ichain 2.2 sp3
    novell ichain 2.2.113
    novell ichain 2.3
    novell ichain 2.3 sp2
    novell ichain 2.2
    novell netware 6.5
    novell ichain 2.3
    novell ichain 2.2 sp1
    novell ichain 2.2 sp2
    novell ichain 2.2 sp3
    novell ichain 2.3 sp2
    novell ichain 2.2.113
    novell netware 5.1
    novell netware 6.0