vendor:
CiscoKits CCNA TFTP Server
by:
Antu Sanadi
7.5
CVSS
HIGH
Directory Traversal
22
CWE
Product Name: CiscoKits CCNA TFTP Server
Affected Version From: 1.0.0.0
Affected Version To: 1.0.0.0
Patch Exists: YES
Related CWE: N/A
CPE: a:certificationkits:cisco_kits_ccna_tftp_server
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2011
CiscoKits TFTP Server Directory Traversal Vulnerability
CiscoKits TFTP Server is vulnerable to directory traversal attack. An attacker can exploit this vulnerability to read any file from the server. The vulnerability exists due to insufficient sanitization of user supplied input in the TFTP Read Request packet. An attacker can send a specially crafted packet with directory traversal characters to read any file from the server.
Mitigation:
Upgrade to the latest version of CiscoKits TFTP Server.