Directory traversal vulnerability in OBEX Push services in Toshiba Bluetooth Stack 4.00.23(T) and earlier allows remote attackers to upload arbitrary files to arbitrary remote locations specified by .. (dot dot) sequences, as demonstrated by ..\\ sequences in the RFILE argument of ussp-push.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 00:05
Type | Values Removed | Values Added |
---|---|---|
References | () http://aps.toshiba-tro.de/bluetooth/pages/driverinfo.php?txt=sp2 - | |
References | () http://marc.info/?l=full-disclosure&m=113712413907526&w=2 - | |
References | () http://secunia.com/advisories/18437 - Vendor Advisory | |
References | () http://securitytracker.com/id?1015486 - | |
References | () http://www.digitalmunition.com/DMA%5B2006-0112a%5D.txt - Exploit, Vendor Advisory | |
References | () http://www.osvdb.org/22380 - | |
References | () http://www.securityfocus.com/archive/1/421993/100/0/threaded - | |
References | () http://www.securityfocus.com/bid/16236 - | |
References | () http://www.vupen.com/english/advisories/2006/0184 - |
Information
Published : 2006-01-14 01:03
Updated : 2024-11-21 00:05
NVD link : CVE-2006-0212
Mitre link : CVE-2006-0212
CVE.ORG link : CVE-2006-0212
JSON object : View
Products Affected
toshiba
- bluetooth_stack
CWE