5

CVE-2006-0212

Exploit
Directory traversal vulnerability in OBEX Push services in Toshiba Bluetooth Stack 4.00.23(T) and earlier allows remote attackers to upload arbitrary files to arbitrary remote locations specified by .. (dot dot) sequences, as demonstrated by ..\\ sequences in the RFILE argument of ussp-push.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ToshibaBluetooth Stack Version <= 4.00.23t
ToshibaBluetooth Stack Version3.00.11
ToshibaBluetooth Stack Version3.00.12
ToshibaBluetooth Stack Version3.00.31a
ToshibaBluetooth Stack Version3.00.32
ToshibaBluetooth Stack Version3.01.03
ToshibaBluetooth Stack Version3.10.00
ToshibaBluetooth Stack Version3.20.00
ToshibaBluetooth Stack Version3.20.01
ToshibaBluetooth Stack Version3.20.02
ToshibaBluetooth Stack Version3.20.04
ToshibaBluetooth Stack Version4.00.01t
ToshibaBluetooth Stack Version4.00.11
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.49% 0.826
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://aps.toshiba-tro.de/bluetooth/pages/driverinfo.php?txt=sp2
http://marc.info/?l=full-disclosure&m=113712413907526&w=2
http://secunia.com/advisories/18437
Vendor Advisory
http://securitytracker.com/id?1015486
http://www.digitalmunition.com/DMA%5B2006-0112a%5D.txt
Vendor Advisory
Exploit
http://www.osvdb.org/22380
http://www.securityfocus.com/archive/1/421993/100/0/threaded
http://www.securityfocus.com/bid/16236
http://www.vupen.com/english/advisories/2006/0184