Description
Directory traversal vulnerability in the PXE Server (pxesrv.exe) in Acronis Snap Deploy 2.0.0.1076 and earlier allows remote attackers to read arbitrary files via directory traversal sequences to the TFTP service.
Affected products
- Acronis / snap_deploy2.0.0.1076 – 2.0.0.1076
References
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/41074
- MISChttp://aluigi.altervista.org/adv/acropxe-adv.txt
- VENDOR_ADVISORYhttp://www.vupen.com/english/advisories/2008/0814/references
- MISChttp://www.securityfocus.com/bid/28182
- MISChttp://www.securityfocus.com/archive/1/489358/100/0/threaded
- VENDOR_ADVISORYhttp://secunia.com/advisories/29305
- MISChttp://securityreason.com/securityalert/3758
- EXPLOIThttps://www.exploit-db.com/exploits/5228