vendor:
Deepin TFTP Server
by:
demonalex
5,5
CVSS
MEDIUM
Directory Traversal
22
CWE
Product Name: Deepin TFTP Server
Affected Version From: v1.25
Affected Version To: v1.25
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2010
Deepin TFTP Server Directory Traversal Vulnerability
Deepin TFTP Server does not properly sanitise filenames containing directory traversal sequences that are received from an FTP client. An attacker can use this vulnerability to gain access to sensitive files on the server. Proof of concept code is provided to demonstrate the vulnerability. Exploit code is provided to demonstrate how an attacker can use this vulnerability to gain access to sensitive files on the server.
Mitigation:
Ensure that the server is configured to properly sanitise filenames containing directory traversal sequences.