CVE-2005-1025
IBM iSeries AS/400 4.3 - Information Disclosure via FTP Symlink Attack
Title source: llmDescription
The FTP server in AS/400 4.3, when running in IFS mode, allows remote attackers to obtain sensitive information via a symlink attack using RCMD and the ADDLNK utility, as demonstrated using the QSYS.LIB library.
References (3)
Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://www.osvdb.org/15300
Exploit x_refsource_misc
http://www.venera.com/downloads/AS400_user_accounts_ftp_disclosure.pdf
Mailing List mailing-list
x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=111264136829017&w=2
Scores
EPSS
0.0232
EPSS Percentile
81.7%
Details
Status
published
Products (1)
ibm/iseries_as_400
4.3
Published
May 02, 2005
Tracked Since
Feb 18, 2026