CVE-2006-1654 Information

Description

Directory traversal vulnerability in the HP Color LaserJet 2500 Toolbox and Color LaserJet 4600 Toolbox on Microsoft Windows before 20060402 allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP GET request to TCP port 5225.

Reference

http://archives.neohapsis.com/archives/fulldisclosure/2006-04/0085.html http://secunia.com/advisories/19529 http://securitytracker.com/id?1015862 http://www.osvdb.org/24396 http://www.securityfocus.com/archive/1/429893/100/0/threaded http://www.securityfocus.com/archive/1/429984/100/0/threaded http://www.securityfocus.com/bid/17367 http://www.vupen.com/english/advisories/2006/1230 https://exchange.xforce.ibmcloud.com/vulnerabilities/25627

Share on: