CVE-2012-6664

CRITICAL

Distinct Intranet Servers <3.10 - Path Traversal

Title source: llm

Description

Multiple directory traversal vulnerabilities in the TFTP Server in Distinct Intranet Servers 3.10 and earlier allow remote attackers to read or write arbitrary files via a .. (dot dot) in the (1) get or (2) put commands.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubywebappswindows
https://www.exploit-db.com/exploits/41714
metasploit WORKING POC EXCELLENT
by modpr0be, sinn3r · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/tftp/distinct_tftp_traversal.rb

Scores

CVSS v3 9.1
EPSS 0.7347
EPSS Percentile 98.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Details

CWE
CWE-22
Status published
Published Jun 21, 2024
Tracked Since Feb 18, 2026