Directory traversal vulnerability in the HP Color LaserJet 2500 Toolbox and Color LaserJet 4600 Toolbox on Microsoft Windows before 20060402 allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP GET request to TCP port 5225.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Color_laserjet_2500_toolbox | Hp | * | * |
Color_laserjet_4600_toolbox | Hp | * | * |
Color_laserjet | Hp | 4600dn (including) | 4600dn (including) |
Color_laserjet | Hp | 4600dtn (including) | 4600dtn (including) |
Color_laserjet | Hp | 4600hdn (including) | 4600hdn (including) |
Color_laserjet_2500 | Hp | * | * |
Color_laserjet_2500l | Hp | * | * |
Color_laserjet_2500lse | Hp | * | * |
Color_laserjet_2500n | Hp | * | * |
Color_laserjet_2500tn | Hp | * | * |
Color_laserjet_4600 | Hp | * | * |