First published: Thu Feb 10 2005(Updated: )
The FTP service in 3Com 3CDaemon 2.0 revision 10 allows remote attackers to gain sensitive information via a cd command that contains an MS-DOS device name, which reveals the installation path in an error message.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
3Com 3CDaemon | =2.0-revision_10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-0278 is classified with a medium severity level due to its potential for information disclosure.
To mitigate CVE-2005-0278, ensure that the 3Com 3CDaemon FTP service is updated to a version that addresses this vulnerability.
CVE-2005-0278 can expose sensitive information such as the installation path of the FTP service.
CVE-2005-0278 affects users running 3Com 3CDaemon version 2.0 revision 10, particularly those using the FTP service.
Yes, CVE-2005-0278 can be exploited remotely by attackers using specific commands to retrieve sensitive information.