CVE-2005-0978

IVT BlueSoleil 1.4 - Path Traversal

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2005-0978. PoCs published by Kevin Finisterre.

AI-analyzed exploit summary This exploit modifies the obextool client to perform a directory traversal attack during Bluetooth file uploads, allowing an attacker to upload a malicious file to arbitrary locations on the target system. The vulnerability lies in the Object Push Service of BlueSoleil, enabling arbitrary code execution if the file is placed in an executable path.

Description

Directory traversal vulnerability in the Object Push service in IVT BlueSoleil 1.4 allows remote attackers to upload arbitrary files via a .. (dot dot) in a PUSH command.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Kevin Finisterre · textremotewindows
https://www.exploit-db.com/exploits/25325

This exploit modifies the obextool client to perform a directory traversal attack during Bluetooth file uploads, allowing an attacker to upload a malicious file to arbitrary locations on the target system. The vulnerability lies in the Object Push Service of BlueSoleil, enabling arbitrary code execution if the file is placed in an executable path.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: BlueSoleil (version not specified)
No auth needed
Prerequisites: Bluetooth connectivity to the target · obextool client modified as shown
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=111238511206503&w=2
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/14790/
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/19930
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/12961

Scores

EPSS 0.0245
EPSS Percentile 82.2%

Details

Status published
Products (1)
ivt/bluesoleil 1.4
Published May 02, 2005
Tracked Since Feb 18, 2026