First published: Mon Apr 24 2006(Updated: )
Directory traversal vulnerability in SolarWinds TFTP Server 8.1 and earlier allows remote attackers to download arbitrary files via a crafted GET request including "....//" sequences, which are collapsed into "../" sequences by filtering.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SolarWinds TFTP Server | =8.1 | |
SolarWinds TFTP Server | =5.0.60standard | |
SolarWinds TFTP Server | =5.0.55_standard |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-1951 is classified as a medium severity vulnerability due to its potential for exposing sensitive files through directory traversal.
To fix CVE-2006-1951, upgrade SolarWinds TFTP Server to version 8.2 or later, as this version addresses the directory traversal vulnerability.
CVE-2006-1951 affects SolarWinds TFTP Server version 8.1 and earlier, as well as versions 5.0.60 standard and 5.0.55 standard.
CVE-2006-1951 can be exploited by remote attackers who send crafted GET requests to download arbitrary files from the server.
While the immediate threat of CVE-2006-1951 is lower for current systems, any outdated software still running vulnerable versions poses a risk.