Vulnerability Description
Directory traversal vulnerability in the HP Color LaserJet 2500 Toolbox and Color LaserJet 4600 Toolbox on Microsoft Windows before 20060402 allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP GET request to TCP port 5225.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hp | Color Laserjet 2500 Toolbox | All versions |
| Hp | Color Laserjet 4600 Toolbox | All versions |
| Hp | Color Laserjet | 4600dn |
| Hp | Color Laserjet 2500 | All versions |
| Hp | Color Laserjet 2500L | All versions |
| Hp | Color Laserjet 2500Lse | All versions |
| Hp | Color Laserjet 2500N | All versions |
| Hp | Color Laserjet 2500Tn | All versions |
| Hp | Color Laserjet 4600 | All versions |
References
- http://archives.neohapsis.com/archives/fulldisclosure/2006-04/0085.htmlExploitPatch
- http://secunia.com/advisories/19529
- http://securitytracker.com/id?1015862ExploitPatch
- http://www.osvdb.org/24396
- http://www.securityfocus.com/archive/1/429893/100/0/threaded
- http://www.securityfocus.com/archive/1/429984/100/0/threaded
- http://www.securityfocus.com/bid/17367Exploit
- http://www.vupen.com/english/advisories/2006/1230
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25627
- http://archives.neohapsis.com/archives/fulldisclosure/2006-04/0085.htmlExploitPatch
- http://secunia.com/advisories/19529
- http://securitytracker.com/id?1015862ExploitPatch
- http://www.osvdb.org/24396
- http://www.securityfocus.com/archive/1/429893/100/0/threaded
- http://www.securityfocus.com/archive/1/429984/100/0/threaded
FAQ
What is CVE-2006-1654?
CVE-2006-1654 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Directory traversal vulnerability in the HP Color LaserJet 2500 Toolbox and Color LaserJet 4600 Toolbox on Microsoft Windows before 20060402 allows remote attackers to read arbitrary files via a .. (d...
How severe is CVE-2006-1654?
CVE-2006-1654 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2006-1654?
Check the references section above for vendor advisories and patch information. Affected products include: Hp Color Laserjet 2500 Toolbox, Hp Color Laserjet 4600 Toolbox, Hp Color Laserjet, Hp Color Laserjet 2500, Hp Color Laserjet 2500L.