CVE-2006-0212
N/A
N/A
Summary
Directory traversal vulnerability in OBEX Push services in Toshiba Bluetooth Stack 4.00.23(T) and earlier allows remote attackers to upload arbitrary files to arbitrary remote locations specified by .. (dot dot) sequences, as demonstrated by ..\ sequences in the RFILE argument of ussp-push.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://www.securityfocus.com/archive/1/421993/100/0/threaded
- http://aps.toshiba-tro.de/bluetooth/pages/driverinfo.php?txt=sp2
- http://www.securityfocus.com/bid/16236
- http://www.vupen.com/english/advisories/2006/0184
- http://secunia.com/advisories/18437
- http://www.digitalmunition.com/DMA%5B2006-0112a%5D.txt
- http://www.osvdb.org/22380
- http://marc.info/?l=full-disclosure&m=113712413907526&w=2
- http://securitytracker.com/id?1015486
References
- http://www.securityfocus.com/archive/1/421993/100/0/threaded
- http://aps.toshiba-tro.de/bluetooth/pages/driverinfo.php?txt=sp2
- http://www.securityfocus.com/bid/16236
- http://www.vupen.com/english/advisories/2006/0184
- http://secunia.com/advisories/18437
- http://www.digitalmunition.com/DMA%5B2006-0112a%5D.txt
- http://www.osvdb.org/22380
- http://marc.info/?l=full-disclosure&m=113712413907526&w=2
- http://securitytracker.com/id?1015486
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.