Description
Bluetooth FTP client (BTFTP) in Nokia Affix 2.1.2 and 3.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename argument of a PUT command.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Kevin Finisterre · textremotehardware
https://www.exploit-db.com/exploits/25966
References (6)
Core 6
Core References
Product x_refsource_confirm
http://affix.sourceforge.net/affix_212_sec.patch
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/14232
Various Sources x_refsource_misc
http://www.digitalmunition.com/DMA%5B2005-0712b%5D.txt
Product x_refsource_confirm
http://affix.sourceforge.net/affix_320_sec.patch
Mailing List mailing-list
x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=112119962704397&w=2
Third Party Advisory vendor-advisory
x_refsource_debian
http://www.debian.org/security/2005/dsa-762
Scores
EPSS
0.0722
EPSS Percentile
91.6%
Details
Status
published
Products (2)
nokia/affix
2.1.2
nokia/affix
3.2.0
Published
Jul 15, 2005
Tracked Since
Feb 18, 2026