ID

VAR-201107-0324


TITLE

Android HTC FTP Service Directory Traversal Vulnerability

Trust: 0.6

sources: CNVD: CNVD-2011-2825

DESCRIPTION

HTC is a popular smartphone. A directory traversal vulnerability exists in the Bluetooth OBEX FTP service provided by HTC devices running on Android 2.1 and Android 2.2 platforms. This vulnerability allows remote authenticated attackers to submit arbitrary directories and read arbitrary by submitting ../ pathname requests. file. Exploiting this issue allows an attacker to read or download arbitrary files from locations outside the application's current directory and obtain sensitive information. Other attacks may also be possible

Trust: 0.81

sources: CNVD: CNVD-2011-2825 // BID: 48821

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2011-2825

AFFECTED PRODUCTS

vendor:htcmodel:ariascope: - version: -

Trust: 0.6

vendor:htcmodel:desire hdscope: - version: -

Trust: 0.6

vendor:htcmodel:wildfirescope: - version: -

Trust: 0.6

vendor:htcmodel:wildfirescope:eqversion:0

Trust: 0.3

vendor:htcmodel:desire hdscope:eqversion:0

Trust: 0.3

vendor:htcmodel:ariascope:eqversion:0

Trust: 0.3

sources: CNVD: CNVD-2011-2825 // BID: 48821

THREAT TYPE

network

Trust: 0.3

sources: BID: 48821

TYPE

Input Validation Error

Trust: 0.3

sources: BID: 48821

EXTERNAL IDS

db:BIDid:48821

Trust: 0.9

db:CNVDid:CNVD-2011-2825

Trust: 0.6

sources: CNVD: CNVD-2011-2825 // BID: 48821

REFERENCES

url:http://www.seguridadmobile.com/android/android-security/htc-android-obex-ftp-service-directory-traversal.html

Trust: 0.9

url:http://www.htc.com/www/

Trust: 0.3

sources: CNVD: CNVD-2011-2825 // BID: 48821

CREDITS

Alberto Moreno Tablado

Trust: 0.3

sources: BID: 48821

SOURCES

db:CNVDid:CNVD-2011-2825
db:BIDid:48821

LAST UPDATE DATE

2022-05-17T02:01:21.551000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2011-2825date:2011-07-22T00:00:00
db:BIDid:48821date:2011-07-20T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2011-2825date:2011-07-22T00:00:00
db:BIDid:48821date:2011-07-20T00:00:00