CVE-2006-4003

high

Description

The config method in Henrik Storner Hobbit monitor before 4.1.2p2 permits access to files outside of the intended configuration directory, which allows remote attackers to obtain sensitive information via requests to the hobbitd daemon on port 1984/tcp.

References

https://exchange.xforce.ibmcloud.com/vulnerabilities/28204

http://www.vupen.com/english/advisories/2006/3139

http://www.securityfocus.com/bid/19317

http://www.securityfocus.com/archive/1/442036/100/0/threaded

http://sourceforge.net/project/shownotes.php?release_id=436594&group_id=128058

http://secunia.com/advisories/21317

Details

Source: Mitre, NVD

Published: 2006-08-07

Updated: 2024-11-21

Risk Information

CVSS v2

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

Severity: Medium

CVSS v3

Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Severity: High