vendor:
BlueSoleil
by:
SecurityFocus
7.5
CVSS
HIGH
Directory Traversal
22
CWE
Product Name: BlueSoleil
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2005
BlueSoleil Directory Traversal Vulnerability
BlueSoleil is prone to directory traversal attacks during Bluetooth file uploads. The issue exists in the Object Push Service. This vulnerability may allow an attacker to upload malicious files to arbitrary locations on affected computers over Bluetooth. An attacker can take advantage of the issue to execute arbitrary code by uploading executables to a location on the computer where they will later be executed. The modified obextool client may then be used to push a malicious file to a target computer.
Mitigation:
Ensure that Bluetooth file uploads are restricted to trusted sources.