Exploitation Summary
EIP tracks 1 public exploit for CVE-2002-1209. PoCs published by Matthew Murphy.
AI-analyzed exploit summary This exploit demonstrates a directory traversal vulnerability in SolarWinds TFTP Server, allowing remote users to download arbitrary files accessible to the TFTP Server user. The PoC uses a malformed filename with traversal sequences to fetch the SAM file from the Windows repair directory.
Description
Directory traversal vulnerability in SolarWinds TFTP Server 5.0.55, and possibly earlier, allows remote attackers to read arbitrary files via "..\" (dot-dot backslash) sequences in a GET request.
Exploits (1)
This exploit demonstrates a directory traversal vulnerability in SolarWinds TFTP Server, allowing remote users to download arbitrary files accessible to the TFTP Server user. The PoC uses a malformed filename with traversal sequences to fetch the SAM file from the Windows repair directory.