Vulnerabilities > CVE-2005-1240 - Unspecified vulnerability in Castlehill Secure NET
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Directory traversal vulnerability in the third party tool from Castlehill, as used to secure the iSeries AS/400 FTP server, allows remote attackers to access arbitrary files, including those from qsys.lib, via ".." sequences in a GET request.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
References
- http://www.securityfocus.com/archive/1/396628
- http://www.securityfocus.com/archive/1/396628
- http://www.venera.com/downloads/Canonicalization_problems_in_iSeries_FTP_security.pdf
- http://www.venera.com/downloads/Canonicalization_problems_in_iSeries_FTP_security.pdf
- https://exchange.xforce.ibmcloud.com/vulnerabilities/20260
- https://exchange.xforce.ibmcloud.com/vulnerabilities/20260