First published: Mon Apr 05 2010(Updated: )
NWFTPD.nlm before 5.08.06 in the FTP server in Novell NetWare does not properly handle partial matches for container names in the FTPREST.TXT file, which allows remote attackers to bypass intended access restrictions via an FTP session.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Novell Netware Ftp Server | ||
Novell NetWare |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-6735 has been classified as a medium severity vulnerability that can allow remote attackers to bypass security restrictions.
To fix CVE-2007-6735, it's recommended to upgrade the NWFTPD.nlm to version 5.08.06 or later.
CVE-2007-6735 affects users of Novell NetWare and the Novell NetWare FTP Server prior to version 5.08.06.
Attackers can exploit CVE-2007-6735 to bypass access restrictions, allowing unauthorized FTP access to system files.
CVE-2007-6735 primarily affects older versions of Novell NetWare; however, any unresolved systems still using these versions may be at risk.