Exploitation Summary
EIP tracks 1 public exploit for CVE-2005-2277. PoCs published by Kevin Finisterre.
AI-analyzed exploit summary This exploit demonstrates a remote command execution vulnerability in Nokia Affix btsrv/btobex due to insufficient input sanitization in a 'system()' call. The PoC shows how an attacker can execute arbitrary commands (e.g., 'id') via FTP by embedding them in a filename.
Description
Bluetooth FTP client (BTFTP) in Nokia Affix 2.1.2 and 3.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename argument of a PUT command.
Exploits (1)
This exploit demonstrates a remote command execution vulnerability in Nokia Affix btsrv/btobex due to insufficient input sanitization in a 'system()' call. The PoC shows how an attacker can execute arbitrary commands (e.g., 'id') via FTP by embedding them in a filename.