vendor:
WhatsUp Gold TFTP Server
by:
Prabhu S Angadi
5
CVSS
MEDIUM
Directory Traversal
22
CWE
Product Name: WhatsUp Gold TFTP Server
Affected Version From: Ipswitch TFTP Server 1.0.0.24
Affected Version To: Ipswitch TFTP Server 1.0.0.24
Patch Exists: NO
Related CWE: N/A
CPE: a:ipswitch:whatsup_gold_tftp_server:1.0.0.24
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP3 & Windows 7
2011
Ipswitch TFTP Server Directory Traversal Vulnerability
The vulnerability is caused due to improper validation to Read Request containing '../' sequences, which allows attackers to read arbitrary files.
Mitigation:
Not available