DEEPIN TFTP Server Directory Traversal Vulnerability
BID:42739
Info
DEEPIN TFTP Server Directory Traversal Vulnerability
| Bugtraq ID: | 42739 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 25 2010 12:00AM |
| Updated: | Aug 25 2010 12:00AM |
| Credit: | demonalex(at)163(dot)com |
| Vulnerable: |
DEEPIN TFTP Server 1.25 |
| Not Vulnerable: | |
Discussion
DEEPIN TFTP Server Directory Traversal Vulnerability
DEEPIN TFTP Server is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input.
Exploiting this issue can allow an attacker to download or upload arbitrary files outside of the document root directory. This may aid in further attacks.
DEEPIN TFTP Server 1.25 is vulnerable; other versions may be affected.
DEEPIN TFTP Server is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input.
Exploiting this issue can allow an attacker to download or upload arbitrary files outside of the document root directory. This may aid in further attacks.
DEEPIN TFTP Server 1.25 is vulnerable; other versions may be affected.
Exploit / POC
DEEPIN TFTP Server Directory Traversal Vulnerability
Attackers can use readily available tools and commands to exploit this issue.
The following proofs of concept and exploit is available:
Attackers can use readily available tools and commands to exploit this issue.
The following proofs of concept and exploit is available:
Solution / Fix
DEEPIN TFTP Server Directory Traversal Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
DEEPIN TFTP Server Directory Traversal Vulnerability
References:
References: