CVE-2004-1948
Summary
| CVE | CVE-2004-1948 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2004-04-20 04:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | NcFTP client 3.1.6 and 3.1.7, when the username and password are included in an FTP URL that is provided on the command line, allows local users to obtain sensitive information via "ps aux," which displays the URL in the process list. |
Risk And Classification
Primary CVSS: v2.0 4.6 from [email protected]
AV:L/AC:L/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:L/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ncftp Software | Ncftp | 3.0.0 | All | All | All |
| Application | Ncftp Software | Ncftp | 3.0.1 | All | All | All |
| Application | Ncftp Software | Ncftp | 3.0.2 | All | All | All |
| Application | Ncftp Software | Ncftp | 3.0.3 | All | All | All |
| Application | Ncftp Software | Ncftp | 3.0.4 | All | All | All |
| Application | Ncftp Software | Ncftp | 3.1.0 | All | All | All |
| Application | Ncftp Software | Ncftp | 3.1.1 | All | All | All |
| Application | Ncftp Software | Ncftp | 3.1.2 | All | All | All |
| Application | Ncftp Software | Ncftp | 3.1.3 | All | All | All |
| Application | Ncftp Software | Ncftp | 3.1.4 | All | All | All |
| Application | Ncftp Software | Ncftp | 3.1.5 | All | All | All |
| Application | Ncftp Software | Ncftp | 3.1.6 | All | All | All |
| Application | Ncftp Software | Ncftp | 3.1.7 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Secunia - Advisories - NcFTP Client Password Leakage Security Issue | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Exploit, Vendor Advisory |
| 'NcFTP - password leaking' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| www.osvdb.org/5595 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| NcFTP Local Information Disclosure Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.