CVE-2002-2353

Tftpd32 - Access Control

Title source: rule
STIX 2.1

Description

tftpd32 2.50 and 2.50.2 allows remote attackers to read or write arbitrary files via a full pathname in GET and PUT requests.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Aviram Jenik · textremotewindows
https://www.exploit-db.com/exploits/22024

References (5)

Core 5
Core References
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/632633
Third Party Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/10646.php
Exploit, Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/6198
Various Sources x_refsource_confirm
http://tftpd32.jounin.net/

Scores

EPSS 0.0484
EPSS Percentile 89.6%

Details

CWE
CWE-264
Status published
Products (2)
tftpd32/tftpd32 2.50
tftpd32/tftpd32 2.50.2
Published Dec 31, 2002
Tracked Since Feb 18, 2026