Vulnerabilities > CVE-2004-0951 - Unspecified vulnerability in HP Ignite-Ux C.6.2.241
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN hp
nessus
Summary
The make_recovery command for the TFTP server in HP Ignite-UX before C.6.2.241 makes a copy of the password file in the TFTP directory tree, which allows remote attackers to obtain sensitive information.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Nessus
NASL family | Misc. |
NASL id | TFTP_FILES_HP_IGNITE_UX_PASSWD.NASL |
description | The remote host has a vulnerable version of the HP Ignite-UX application installed that exposes the /etc/passwd file to anonymous TFTP access. A remote attacker could use this information to mount further attacks. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 19509 |
published | 2005-08-26 |
reporter | This NASL script is Copyright (C) 2005-2018 Corsaire Limited. |
source | https://www.tenable.com/plugins/nessus/19509 |
title | HP Ignite-UX TFTP /etc/pass File Disclosure |
code |
|
References
- http://secunia.com/advisories/16456/
- http://secunia.com/advisories/16456/
- http://securitytracker.com/id?1014711
- http://securitytracker.com/id?1014711
- http://www.corsaire.com/advisories/c041123-001.txt
- http://www.corsaire.com/advisories/c041123-001.txt
- http://www.securityfocus.com/bid/14568
- http://www.securityfocus.com/bid/14568
- https://exchange.xforce.ibmcloud.com/vulnerabilities/21858
- https://exchange.xforce.ibmcloud.com/vulnerabilities/21858