Vulnerabilities > CVE-2006-4003 - Unspecified vulnerability in Hobbit Monitor Hobbit Monitor 4.0/4.1
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN hobbit-monitor
nessus
Summary
The config method in Henrik Storner Hobbit monitor before 4.1.2p2 permits access to files outside of the intended configuration directory, which allows remote attackers to obtain sensitive information via requests to the hobbitd daemon on port 1984/tcp.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 3 |
Nessus
NASL family | Misc. |
NASL id | HOBBITD_CONFIG_DIR_TRAVERSAL.NASL |
description | The version of the Hobbit Monitor daemon installed on the remote host does not properly filter the argument to the |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 22181 |
published | 2006-08-08 |
reporter | This script is Copyright (C) 2006-2018 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/22181 |
title | Hobbit Monitor config Method Traversal Arbitrary File Access |
code |
|
References
- http://secunia.com/advisories/21317
- http://secunia.com/advisories/21317
- http://sourceforge.net/project/shownotes.php?release_id=436594&group_id=128058
- http://sourceforge.net/project/shownotes.php?release_id=436594&group_id=128058
- http://www.securityfocus.com/archive/1/442036/100/0/threaded
- http://www.securityfocus.com/archive/1/442036/100/0/threaded
- http://www.securityfocus.com/bid/19317
- http://www.securityfocus.com/bid/19317
- http://www.vupen.com/english/advisories/2006/3139
- http://www.vupen.com/english/advisories/2006/3139
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28204
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28204