7.8
CVSSv2

CVE-2011-4722

Published: 28/12/2014 Updated: 29/08/2017
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 785
Vector: AV:N/AC:L/Au:N/C:C/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in the TFTP Server 1.0.0.24 in Ipswitch WhatsUp Gold allows remote malicious users to read arbitrary files via a .. (dot dot) in the Filename field of an RRQ operation.

Vulnerable Product Search on Vulmon Subscribe to Product

ipswitch tftp server 1.0.0.24

Vendor Advisories

Potential Security Impact: Remote read access to arbitrary files Source: HP, HP Product Security Response Team (PSRT) Reported By: Thomas Sundell, Uppsala University VULNERABILITY SUMMARY Directory traversal vulnerability in the TFTP Server 10024 in Ipswitch WhatsUp Gold allows remote attackers to read arbitrary files v ...

Exploits

############################################################################## # Title : Ipswitch TFTP Server Directory Traversal Vulnerability # Author : Prabhu S Angadi from SecPod Technologies (wwwsecpodcom) # Vendor : wwwwhatsupgoldcom/indexaspx # Advisory : secpodorg/blog/?p=424 # secpodorg/ad ...