{"api_version":"1","generated_at":"2026-07-23T09:31:42+00:00","cve":"CVE-2005-3630","urls":{"html":"https://cve.report/CVE-2005-3630","api":"https://cve.report/api/cve/CVE-2005-3630.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-3630","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-3630"},"summary":{"title":"CVE-2005-3630","description":"Fedora Directory Server before 10 allows remote attackers to obtain sensitive information, such as the password from adm.conf via an IFRAME element, probably involving an Apache httpd.conf configuration that orders \"allow\" directives before \"deny\" directives.","state":"PUBLISHED","assigner":"redhat","published_at":"2005-12-31 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=174837","name":"https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=174837","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"174837 – CVE-2005-3630 use of IFRAME exposes password from adm.conf for users","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/16729","name":"http://www.securityfocus.com/bid/16729","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Fedora Directory Server Password Information Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://bugzilla.redhat.com/bugzilla/attachment.cgi?id=121994","name":"https://bugzilla.redhat.com/bugzilla/attachment.cgi?id=121994","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"","mime":"text/x-diff","httpstatus":"200","archivestatus":"200"},{"url":"http://directory.fedora.redhat.com/wiki/FDS10Announcement","name":"http://directory.fedora.redhat.com/wiki/FDS10Announcement","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"FDS10Announcement - Fedora Directory Server","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://secunia.com/advisories/18939","name":"http://secunia.com/advisories/18939","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Secunia - Advisories - Fedora Directory Server Admin Server Password Disclosure","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-3630","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-3630","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"3630","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"redhat","cpe5":"fedora_core","cpe6":"1.0","cpe7":"*","cpe8":"directory_server","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T23:17:23.700Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://directory.fedora.redhat.com/wiki/FDS10Announcement"},{"name":"16729","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/16729"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://bugzilla.redhat.com/bugzilla/attachment.cgi?id=121994"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=174837"},{"name":"18939","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/18939"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"descriptions":[{"lang":"en","value":"Fedora Directory Server before 10 allows remote attackers to obtain sensitive information, such as the password from adm.conf via an IFRAME element, probably involving an Apache httpd.conf configuration that orders \"allow\" directives before \"deny\" directives."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2006-02-24T00:00:00.000Z","orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://directory.fedora.redhat.com/wiki/FDS10Announcement"},{"name":"16729","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/16729"},{"tags":["x_refsource_MISC"],"url":"https://bugzilla.redhat.com/bugzilla/attachment.cgi?id=121994"},{"tags":["x_refsource_CONFIRM"],"url":"https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=174837"},{"name":"18939","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/18939"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"secalert@redhat.com","ID":"CVE-2005-3630","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Fedora Directory Server before 10 allows remote attackers to obtain sensitive information, such as the password from adm.conf via an IFRAME element, probably involving an Apache httpd.conf configuration that orders \"allow\" directives before \"deny\" directives."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://directory.fedora.redhat.com/wiki/FDS10Announcement","refsource":"CONFIRM","url":"http://directory.fedora.redhat.com/wiki/FDS10Announcement"},{"name":"16729","refsource":"BID","url":"http://www.securityfocus.com/bid/16729"},{"name":"https://bugzilla.redhat.com/bugzilla/attachment.cgi?id=121994","refsource":"MISC","url":"https://bugzilla.redhat.com/bugzilla/attachment.cgi?id=121994"},{"name":"https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=174837","refsource":"CONFIRM","url":"https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=174837"},{"name":"18939","refsource":"SECUNIA","url":"http://secunia.com/advisories/18939"}]}}}},"cveMetadata":{"assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","cveId":"CVE-2005-3630","datePublished":"2006-02-24T00:00:00.000Z","dateReserved":"2005-11-16T00:00:00.000Z","dateUpdated":"2024-09-17T01:21:04.219Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-12-31 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:redhat:fedora_core:1.0:*:directory_server:*:*:*:*:*","matchCriteriaId":"883A1946-9017-4FA7-9517-2D074E764B14"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"3630","Ordinal":"1","Title":"CVE-2005-3630","CVE":"CVE-2005-3630","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"3630","Ordinal":"1","NoteData":"Fedora Directory Server before 10 allows remote attackers to obtain sensitive information, such as the password from adm.conf via an IFRAME element, probably involving an Apache httpd.conf configuration that orders \"allow\" directives before \"deny\" directives.","Type":"Description","Title":"CVE-2005-3630"},{"CveYear":"2005","CveId":"3630","Ordinal":"2","NoteData":"2006-02-23","Type":"Other","Title":"Published"}]}}}