First published: Wed Jan 21 2009(Updated: )
Directory traversal vulnerability in the OBEX FTP Service in the Microsoft Bluetooth stack in Windows Mobile 6 Professional, and probably Windows Mobile 5.0 for Pocket PC and 5.0 for Pocket PC Phone Edition, allows remote authenticated users to list arbitrary directories, and create or read arbitrary files, via a .. (dot dot) in a pathname. NOTE: this can be leveraged for code execution by writing to a Startup folder.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows Mobile | =6.0 | |
Microsoft Windows Mobile | =6.0 | |
Microsoft Windows Mobile | =5.0 | |
Microsoft Windows Mobile | =5.0 | |
Microsoft Windows Mobile | =6.0 | |
Microsoft Windows Mobile | =5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.