{"api_version":"1","generated_at":"2026-07-24T19:47:52+00:00","cve":"CVE-2006-4003","urls":{"html":"https://cve.report/CVE-2006-4003","api":"https://cve.report/api/cve/CVE-2006-4003.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-4003","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-4003"},"summary":{"title":"CVE-2006-4003","description":"The config method in Henrik Storner Hobbit monitor before 4.1.2p2 permits access to files outside of the intended configuration directory, which allows remote attackers to obtain sensitive information via requests to the hobbitd daemon on port 1984/tcp.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2006-08-07 19:04:00","updated_at":"2018-10-17 21:32:00"},"problem_types":["NVD-CWE-Other"],"metrics":[],"references":[{"url":"http://secunia.com/advisories/21317","name":"21317","refsource":"SECUNIA","tags":["Patch","Vendor Advisory"],"title":"Hobbit Monitor \"config\" Method Information Disclosure - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2006/3139","name":"ADV-2006-3139","refsource":"VUPEN","tags":[],"title":"Webmail | OVH- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/28204","name":"hobbitmonitor-config-information-disclosure(28204)","refsource":"XF","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/19317","name":"19317","refsource":"BID","tags":["Patch"],"title":"Hobbit Monitor Config Information Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.securityfocus.com/archive/1/442036/100/0/threaded","name":"20060802 Hobbit monitor security bugfix release - 4.1.2p2","refsource":"BUGTRAQ","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://sourceforge.net/project/shownotes.php?release_id=436594&group_id=128058","name":"http://sourceforge.net/project/shownotes.php?release_id=436594&group_id=128058","refsource":"CONFIRM","tags":["Patch"],"title":"Xymon systems and network monitor download | SourceForge.net","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-4003","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-4003","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"4003","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"hobbit_monitor","cpe5":"hobbit_monitor","cpe6":"4.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"4003","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"hobbit_monitor","cpe5":"hobbit_monitor","cpe6":"4.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"4003","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"hobbit_monitor","cpe5":"hobbit_monitor","cpe6":"4.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"4003","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"hobbit_monitor","cpe5":"hobbit_monitor","cpe6":"4.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"4003","vulnerable":"1","versionEndIncluding":"4.1.2_p1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"hobbit_monitor","cpe5":"hobbit_monitor","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-4003","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The config method in Henrik Storner Hobbit monitor before 4.1.2p2 permits access to files outside of the intended configuration directory, which allows remote attackers to obtain sensitive information via requests to the hobbitd daemon on port 1984/tcp."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"ADV-2006-3139","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/3139"},{"name":"hobbitmonitor-config-information-disclosure(28204)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/28204"},{"name":"20060802 Hobbit monitor security bugfix release - 4.1.2p2","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/442036/100/0/threaded"},{"name":"19317","refsource":"BID","url":"http://www.securityfocus.com/bid/19317"},{"name":"http://sourceforge.net/project/shownotes.php?release_id=436594&group_id=128058","refsource":"CONFIRM","url":"http://sourceforge.net/project/shownotes.php?release_id=436594&group_id=128058"},{"name":"21317","refsource":"SECUNIA","url":"http://secunia.com/advisories/21317"}]}},"nvd":{"publishedDate":"2006-08-07 19:04:00","lastModifiedDate":"2018-10-17 21:32:00","problem_types":["NVD-CWE-Other"],"metrics":{"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:hobbit_monitor:hobbit_monitor:4.1:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:hobbit_monitor:hobbit_monitor:*:*:*:*:*:*:*:*","versionEndIncluding":"4.1.2_p1","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:hobbit_monitor:hobbit_monitor:4.0:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"4003","Ordinal":"19329","Title":"CVE-2006-4003","CVE":"CVE-2006-4003","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"4003","Ordinal":"1","NoteData":"The config method in Henrik Storner Hobbit monitor before 4.1.2p2 permits access to files outside of the intended configuration directory, which allows remote attackers to obtain sensitive information via requests to the hobbitd daemon on port 1984/tcp.","Type":"Description","Title":null},{"CveYear":"2006","CveId":"4003","Ordinal":"2","NoteData":"2006-08-07","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"4003","Ordinal":"3","NoteData":"2018-10-17","Type":"Other","Title":"Modified"}]}}}