Vulnerability CVE-2004-1948


Published: 2004-04-20   Modified: 2012-02-12

Description:
NcFTP client 3.1.6 and 3.1.7, when the username and password are included in an FTP URL that is provided on the command line, allows local users to obtain sensitive information via "ps aux," which displays the URL in the process list.

CVSS2 => (AV:L/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4.6/10
6.4/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Ncftp software -> Ncftp 

 References:
http://xforce.iss.net/xforce/xfdb/15919
http://www.securityfocus.com/bid/10182
http://secunia.com/advisories/11438
http://marc.theaimsgroup.com/?l=bugtraq&m=108247943201685&w=2
http://www.osvdb.org/5595

Copyright 2024, cxsecurity.com

 

Back to Top