5

CVE-2006-0212

Exploit
Directory traversal vulnerability in OBEX Push services in Toshiba Bluetooth Stack 4.00.23(T) and earlier allows remote attackers to upload arbitrary files to arbitrary remote locations specified by .. (dot dot) sequences, as demonstrated by ..\\ sequences in the RFILE argument of ussp-push.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ToshibaBluetooth Stack Version <= 4.00.23t
ToshibaBluetooth Stack Version3.00.11
ToshibaBluetooth Stack Version3.00.12
ToshibaBluetooth Stack Version3.00.31a
ToshibaBluetooth Stack Version3.00.32
ToshibaBluetooth Stack Version3.01.03
ToshibaBluetooth Stack Version3.10.00
ToshibaBluetooth Stack Version3.20.00
ToshibaBluetooth Stack Version3.20.01
ToshibaBluetooth Stack Version3.20.02
ToshibaBluetooth Stack Version3.20.04
ToshibaBluetooth Stack Version4.00.01t
ToshibaBluetooth Stack Version4.00.11
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.66% 0.804
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.