TFTPD32 2.50 - Arbitrary File Download/Upload
Author: Aviram Jenik type: remote platform: windows port: date_added: 2002-11-18 date_updated: 2012-10-16 verified: 1 codes: CVE-2002-2353;OSVDB-57701 tags: aliases: screenshot_url: application_url: raw file: 22024.txt
source: https://www.securityfocus.com/bid/6198/info A vulnerability has been discovered in Tftpd32 which allows a remote attacker to download and upload arbitrary system files. The ability to upload system files may allow an attacker to replaced key system files with trojaned copies, used to open backdoors into a target system. tftp host GET /boot.ini tftp host PUT myfile /boot.ini