vendor:
Windows Mobile
by:
Alberto Moreno Tablado
8,8
CVSS
HIGH
Directory Traversal
22
CWE
Product Name: Windows Mobile
Affected Version From: Windows Mobile 6
Affected Version To: Windows Mobile 6.1
Patch Exists: YES
Related CWE: CVE-2009-0385
CPE: o:microsoft:windows_mobile:6
Metasploit:
https://www.rapid7.com/db/vulnerabilities/ubuntu-USN-763-1/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2009-0698/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2009-0698/, https://www.rapid7.com/db/vulnerabilities/ubuntu-USN-746-1/, https://www.rapid7.com/db/vulnerabilities/ffmpeg-cve-2009-0385/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2009-0385/, https://www.rapid7.com/db/vulnerabilities/freebsd-vid-6733e1bf-125f-11de-a964-0030843d3802/
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows Mobile 6 and Windows Mobile 6.1
2009
HTC / Windows Mobile OBEX FTP Service Directory Traversal
HTC devices running Windows Mobile 6 and Windows Mobile 6.1 are prone to a directory traversal vulnerability in the Bluetooth OBEX FTP Service. Exploiting this issue allows a remote authenticated attacker to list arbitrary directories, and write or read arbitrary files, via a ../ in a pathname. This can be leveraged for code execution by writing to a Startup folder.
Mitigation:
The vendor has released a patch to address this issue.