CVE-2006-0212: Medium severity Toshiba Bluetooth Stack vulnerability
Directory traversal vulnerability in OBEX Push services in Toshiba Bluetooth Stack 4.00.23(T) and earlier allows remote attackers to upload arbitrary files to arbitrary remote locations specified by .. (dot dot) sequences, as demonstrated by ..\\ sequences in the RFILE argument of ussp-push.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-0212?
CVE-2006-0212 is classified as a high-severity vulnerability due to its potential to allow remote file uploads.
How do I fix CVE-2006-0212?
To fix CVE-2006-0212, update the Toshiba Bluetooth Stack to a version later than 4.00.23(T).
What systems are affected by CVE-2006-0212?
CVE-2006-0212 affects Toshiba Bluetooth Stack versions up to and including 4.00.23(T) as well as several earlier versions.
Can CVE-2006-0212 be exploited remotely?
Yes, CVE-2006-0212 can be exploited remotely through directory traversal techniques with OBEX Push services.
What are the consequences of CVE-2006-0212?
Exploitation of CVE-2006-0212 allows attackers to upload arbitrary files to specified remote locations, potentially leading to system compromise.