Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2006-0212


Directory traversal vulnerability in OBEX Push services in Toshiba Bluetooth Stack 4.00.23(T) and earlier allows remote attackers to upload arbitrary files to arbitrary remote locations specified by .. (dot dot) sequences, as demonstrated by ..\\ sequences in the RFILE argument of ussp-push.


Published

2006-01-14T01:03:00.000

Last Modified

2025-04-03T01:03:51.193

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 5.0 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    NVD-CWE-Other

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application toshiba bluetooth_stack ≤ 4.00.23t Yes
Application toshiba bluetooth_stack 3.00.11 Yes
Application toshiba bluetooth_stack 3.00.12 Yes
Application toshiba bluetooth_stack 3.00.31a Yes
Application toshiba bluetooth_stack 3.00.32 Yes
Application toshiba bluetooth_stack 3.01.03 Yes
Application toshiba bluetooth_stack 3.10.00 Yes
Application toshiba bluetooth_stack 3.20.00 Yes
Application toshiba bluetooth_stack 3.20.01 Yes
Application toshiba bluetooth_stack 3.20.02 Yes
Application toshiba bluetooth_stack 3.20.04 Yes
Application toshiba bluetooth_stack 4.00.01t Yes
Application toshiba bluetooth_stack 4.00.11 Yes

References