CVE Vulnerabilities

CVE-2006-0212

Published: Jan 14, 2006 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Directory traversal vulnerability in OBEX Push services in Toshiba Bluetooth Stack 4.00.23(T) and earlier allows remote attackers to upload arbitrary files to arbitrary remote locations specified by .. (dot dot) sequences, as demonstrated by .. sequences in the RFILE argument of ussp-push.

Affected Software

NameVendorStart VersionEnd Version
Bluetooth_stackToshiba*4.00.23t (including)
Bluetooth_stackToshiba3.00.11 (including)3.00.11 (including)
Bluetooth_stackToshiba3.00.12 (including)3.00.12 (including)
Bluetooth_stackToshiba3.00.31a (including)3.00.31a (including)
Bluetooth_stackToshiba3.00.32 (including)3.00.32 (including)
Bluetooth_stackToshiba3.01.03 (including)3.01.03 (including)
Bluetooth_stackToshiba3.10.00 (including)3.10.00 (including)
Bluetooth_stackToshiba3.20.00 (including)3.20.00 (including)
Bluetooth_stackToshiba3.20.01 (including)3.20.01 (including)
Bluetooth_stackToshiba3.20.02 (including)3.20.02 (including)
Bluetooth_stackToshiba3.20.04 (including)3.20.04 (including)
Bluetooth_stackToshiba4.00.01t (including)4.00.01t (including)
Bluetooth_stackToshiba4.00.11 (including)4.00.11 (including)

References