<dd id="sga4y"><optgroup id="sga4y"></optgroup></dd>
<nav id="sga4y"><code id="sga4y"></code></nav>
  • <optgroup id="sga4y"></optgroup>
    &"nbsp;"
    Beyond-Security's SecuriTeam.com
    &"nbsp;"

     SecuriTeam Home
     About SecuriTeam
     Ask the Team
     Advertising info
     Security News
     Security Reviews
     Exploits
     Tools
     UNIX focus
     Windows NT focus


    E-Mail this article to a friend
    Send us comments
    &"nbsp;"


     Title 17/11/2002
    TFTPD32 Directory Traversal Vulnerability

     Summary
    TFTPD32 is a Freeware TFTP server for windows 9x/NT/XP. It provides an implementation of the TFTPv2 protocol (specified in the RFC 1350).
    A vulnerability in the product allows remote attackers to view any file on the system as well as write to arbitrary locations.

     Details
    Vulnerable systems:
     * TFTP32 version 2.50.2 and prior

    Immune systems:
     * TFTP32 version 2.51

    Exploit:
    Getting files:
    tftp host GET /boot.ini

    Storing files:
    tftp host PUT myfile /boot.ini

     Additional information
    The information has been provided by SecurITeam Experts.
     
    &"nbsp;"
    Copyright ?1998-2001 Beyond Security Ltd. All rights reserved.
    Terms of Use Site Privacy Statement.

    97av