Vulnerability Name: | CVE-2005-3630 (CCN-35250) | ||||||||
Assigned: | 2005-12-02 | ||||||||
Published: | 2005-12-02 | ||||||||
Updated: | 2008-09-05 | ||||||||
Summary: | Fedora Directory Server before 10 allows remote attackers to obtain sensitive information, such as the password from adm.conf via an IFRAME element, probably involving an Apache httpd.conf configuration that orders "allow" directives before "deny" directives. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: MITRE Type: CNA CVE-2005-3630 Source: CONFIRM Type: UNKNOWN http://directory.fedora.redhat.com/wiki/FDS10Announcement Source: CCN Type: Fedora Project Web site Fedora Dirctory Server Project Source: CCN Type: Fedora fds10announcement Announcing Fedora Directory Server 1.0 Source: CCN Type: SA18939 Fedora Directory Server Admin Server Password Disclosure Source: SECUNIA Type: Patch, Vendor Advisory 18939 Source: CCN Type: OSVDB ID: 23350 Fedora Directory Server Crafted IFRAME adm.conf Admin Server Password Disclosure Source: BID Type: Patch 16729 Source: CCN Type: BID-16729 Fedora Directory Server Password Information Disclosure Vulnerability Source: MISC Type: Patch https://bugzilla.redhat.com/bugzilla/attachment.cgi?id=121994 Source: CCN Type: Red Hat Bugzilla Bug 174837 CVE-2005-3630 use of IFRAME exposes password from adm.conf for users Source: CONFIRM Type: UNKNOWN https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=174837 Source: XF Type: UNKNOWN fedora-admconf-information-disclosure(35250) | ||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
BACK |