Directory traversal vulnerability in SolarWinds TFTP Server 8.1 and earlier allows remote attackers to download arbitrary files via a crafted GET request including ….// sequences, which are collapsed into ../ sequences by filtering.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Tftp_server | Solarwinds | 5.0.55_standard (including) | 5.0.55_standard (including) |
Tftp_server | Solarwinds | 5.0.60standard (including) | 5.0.60standard (including) |
Tftp_server | Solarwinds | 8.1 (including) | 8.1 (including) |