CVE-2002-1209
medium · 5Directory traversal vulnerability in SolarWinds TFTP Server 5.0.55, and possibly earlier, allows remote attackers to read arbitrary files via "..\" (dot-dot backslash) sequences in a GET request.
5
CVSS
12.9%
EPSS (exploit prob.)
96th
EPSS percentile
2002-11-04
Published
AV:N/AC:L/Au:N/C:P/I:N/A:N
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| solarwinds | tftp_server | 5.0.55_standard |
Check a specific version with /api/v1/cve/match.
References
- http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0044.html
- http://www.idefense.com/advisory/10.24.02.txt
- http://www.securityfocus.com/bid/6045
- https://exchange.xforce.ibmcloud.com/vulnerabilities/10469
- http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0044.html
- http://www.idefense.com/advisory/10.24.02.txt
- http://www.securityfocus.com/bid/6045
- https://exchange.xforce.ibmcloud.com/vulnerabilities/10469
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2002-1209