Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2009-0244

Опубликовано: 21 янв. 2009
Источник: nvd
CVSS3: 8.8
CVSS2: 8.5
EPSS Средний

Описание

Directory traversal vulnerability in the OBEX FTP Service in the Microsoft Bluetooth stack in Windows Mobile 6 Professional, and probably Windows Mobile 5.0 for Pocket PC and 5.0 for Pocket PC Phone Edition, allows remote authenticated users to list arbitrary directories, and create or read arbitrary files, via a .. (dot dot) in a pathname. NOTE: this can be leveraged for code execution by writing to a Startup folder.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:o:microsoft:windows_mobile:5.0:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_mobile:5.0:*:pocket_pc:*:*:*:*:*
cpe:2.3:o:microsoft:windows_mobile:5.0:*:smartphone:*:*:*:*:*
cpe:2.3:o:microsoft:windows_mobile:6.0:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_mobile:6.0:*:pro:*:*:*:*:*
cpe:2.3:o:microsoft:windows_mobile:6.0:*:standard:*:*:*:*:*

EPSS

Процентиль: 95%
0.17356
Средний

8.8 High

CVSS3

8.5 High

CVSS2

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 8.8
github
почти 4 года назад

Directory traversal vulnerability in the OBEX FTP Service in the Microsoft Bluetooth stack in Windows Mobile 6 Professional, and probably Windows Mobile 5.0 for Pocket PC and 5.0 for Pocket PC Phone Edition, allows remote authenticated users to list arbitrary directories, and create or read arbitrary files, via a .. (dot dot) in a pathname. NOTE: this can be leveraged for code execution by writing to a Startup folder.

EPSS

Процентиль: 95%
0.17356
Средний

8.8 High

CVSS3

8.5 High

CVSS2

Дефекты

CWE-22