5
CVSSv2

CVE-2002-1209

Published: 04/11/2002 Updated: 11/07/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in SolarWinds TFTP Server 5.0.55, and possibly earlier, allows remote malicious users to read arbitrary files via "..\" (dot-dot backslash) sequences in a GET request.

Vulnerable Product Search on Vulmon Subscribe to Product

solarwinds tftp server 5.0.55_standard

Exploits

source: wwwsecurityfocuscom/bid/6045/info SolarWinds TFTP Server is distributed for the Microsoft Windows platform The SolarWinds TFTP Server does not properly handle user-supplied input Due to insufficient handling of user input, it is possible for a remote user to request arbitrary files from the vulnerable server It would be possib ...