CVE-2006-0212

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
14/01/2006
Last modified:
03/04/2025

Description

Directory traversal vulnerability in OBEX Push services in Toshiba Bluetooth Stack 4.00.23(T) and earlier allows remote attackers to upload arbitrary files to arbitrary remote locations specified by .. (dot dot) sequences, as demonstrated by ..\\ sequences in the RFILE argument of ussp-push.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:toshiba:bluetooth_stack:*:*:*:*:*:*:*:* 4.00.23t (including)
cpe:2.3:a:toshiba:bluetooth_stack:3.00.11:*:*:*:*:*:*:*
cpe:2.3:a:toshiba:bluetooth_stack:3.00.12:*:*:*:*:*:*:*
cpe:2.3:a:toshiba:bluetooth_stack:3.00.31a:*:*:*:*:*:*:*
cpe:2.3:a:toshiba:bluetooth_stack:3.00.32:*:*:*:*:*:*:*
cpe:2.3:a:toshiba:bluetooth_stack:3.01.03:*:*:*:*:*:*:*
cpe:2.3:a:toshiba:bluetooth_stack:3.10.00:*:*:*:*:*:*:*
cpe:2.3:a:toshiba:bluetooth_stack:3.20.00:*:*:*:*:*:*:*
cpe:2.3:a:toshiba:bluetooth_stack:3.20.01:*:*:*:*:*:*:*
cpe:2.3:a:toshiba:bluetooth_stack:3.20.02:*:*:*:*:*:*:*
cpe:2.3:a:toshiba:bluetooth_stack:3.20.04:*:*:*:*:*:*:*
cpe:2.3:a:toshiba:bluetooth_stack:4.00.01t:*:*:*:*:*:*:*
cpe:2.3:a:toshiba:bluetooth_stack:4.00.11:*:*:*:*:*:*:*