Directory traversal vulnerability in OBEX Push services in Toshiba Bluetooth Stack 4.00.23(T) and previous versions allows remote malicious users to upload arbitrary files to arbitrary remote locations specified by .. (dot dot) sequences, as demonstrated by ..\\ sequences in the RFILE argument of ussp-push.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
toshiba bluetooth stack 3.01.03 |
||
toshiba bluetooth stack 3.10.00 |
||
toshiba bluetooth stack |
||
toshiba bluetooth stack 3.00.31a |
||
toshiba bluetooth stack 3.00.32 |
||
toshiba bluetooth stack 4.00.01t |
||
toshiba bluetooth stack 4.00.11 |
||
toshiba bluetooth stack 3.20.00 |
||
toshiba bluetooth stack 3.20.01 |
||
toshiba bluetooth stack 3.00.11 |
||
toshiba bluetooth stack 3.00.12 |
||
toshiba bluetooth stack 3.20.02 |
||
toshiba bluetooth stack 3.20.04 |