Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

This site is deprecated. Please CLICK HERE for latest updates

Short Name

TFTP:DIRECTORY:SOLAR-TFTP-TRVRS

Severity

Major

Recommended

No

Recommended Action

Drop

Category

TFTP

Keywords

SolarWinds Directory Traversal

Release Date

2003/04/22

Update Number

1213

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+

TFTP: SolarWinds Directory Traversal


This signature detects directory traversal attempts against the SolarWinds TFTP Server. All versions prior to 5.0.60 are vulnerable. A successful attack can allow attackers to retrieve sensitive system files and use the information to further compromise the TFTP Server.

Extended Description

SolarWinds TFTP Server is distributed for the Microsoft Windows platform. The SolarWinds TFTP Server does not properly handle user-supplied input. Due to insufficient handling of user input, it is possible for a remote user to request arbitrary files from the vulnerable server. It would be possible for a remote user to download any files readable through the permissions of the TFTP Server user.

Affected Products

  • Solarwinds tftp_server_standard_edition 5.0.55

References

  • BugTraq: 6045
  • CVE: CVE-2002-1209
  • URL: http://securityvulns.com/docs3679.html
  • URL: http://support.solarwinds.net/updates/SelectProgramFree.cfm#

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out