Intrusion Prevention

3Com.3CDaemon.FTP.Server.Information.Disclosure

Description

It indicates a possible exploit of information disclosure vulnerability in 3Com 3CDaemon.


3CDaemon is a free TFTP, FTP, and Syslog daemon for Microsoft Windows platforms. A vulnerability is reported in it that allow an attacker retrieve information from server such as installation path A remote attackers to may sensitive information via a cd command that contains an MS-DOS device name, which reveals the installation path in an error message.

Affected Products

3Com 3CDaemon 2.0 revision 10.

Impact

Information disclosure leading to further attacks.

Recommended Actions

Apply appropriate patch from vendor if available.

CVE References

CVE-2005-0278