ID
VAR-190001-0663
TITLE
CiscoKits CCNA TFTP 'Read' Command Directory Traversal Vulnerability
Trust: 1.2
DESCRIPTION
CertificationKits CiscoKits CCNA TFTP Server is a TFTP server that can be used to help prepare for the Cisco Certificate Exam. CertificationKits CiscoKits CCNA TFTP Server incorrectly handles read requests containing \"../\" sequences, allowing an attacker to read arbitrary files through a directory traversal attack. CiscoKits CCNA TFTP Server is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input. Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks
Trust: 0.81
IOT TAXONOMY
category: | ['Network device'] | sub_category: | - | Trust: 0.6 |
AFFECTED PRODUCTS
vendor: | certificationkits | model: | ciscokits ccna tftp server | scope: | eq | version: | 1.0 | Trust: 0.9 |
THREAT TYPE
remote
Trust: 0.6
TYPE
path traversal
Trust: 0.6
EXTERNAL IDS
db: | BID | id: | 49053 | Trust: 1.5 |
db: | CNVD | id: | CNVD-2011-3059 | Trust: 0.6 |
db: | CNNVD | id: | CNNVD-201108-116 | Trust: 0.6 |
REFERENCES
url: | http://secpod.org/advisories/secpod_ciscokits_tftp_server_dir_trav.txt | Trust: 0.9 |
url: | http://www.securityfocus.com/bid/49053 | Trust: 0.6 |
url: | http://www.certificationkits.com/cisco-ccna-tftp-server/ | Trust: 0.3 |
CREDITS
Antu Sanadi of SecPod Research
Trust: 0.9
SOURCES
db: | CNVD | id: | CNVD-2011-3059 |
db: | BID | id: | 49053 |
db: | CNNVD | id: | CNNVD-201108-116 |
LAST UPDATE DATE
2022-05-17T02:10:24.130000+00:00
SOURCES UPDATE DATE
db: | CNVD | id: | CNVD-2011-3059 | date: | 2011-08-08T00:00:00 |
db: | BID | id: | 49053 | date: | 2011-08-05T00:00:00 |
db: | CNNVD | id: | CNNVD-201108-116 | date: | 2011-08-09T00:00:00 |
SOURCES RELEASE DATE
db: | CNVD | id: | CNVD-2011-3059 | date: | 2011-08-08T00:00:00 |
db: | BID | id: | 49053 | date: | 2011-08-05T00:00:00 |
db: | CNNVD | id: | CNNVD-201108-116 | date: | 1900-01-01T00:00:00 |