Directory traversal vulnerability in SolarWinds TFTP Server 8.1 and earlier allows remote attackers to download arbitrary files via a crafted GET request including "....//" sequences, which are collapsed into "../" sequences by filtering.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2006-04-24 16:02
Updated : 2018-10-18 09:37
NVD link : CVE-2006-1951
Mitre link : CVE-2006-1951
JSON object : View
CWE
Products Affected
solarwinds
- tftp_server