CVE-2006-1654
Last modified
CVE-2006-1654 is a vulnerability of currently unknown severity. Directory traversal vulnerability in the HP Color LaserJet 2500 Toolbox and Color LaserJet 4600 Toolbox on Microsoft Windows before 20060402 allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP GET request to TCP port 5225.. EPSS estimates a 4.68% chance of exploitation in the next 30 days.
Description
Directory traversal vulnerability in the HP Color LaserJet 2500 Toolbox and Color LaserJet 4600 Toolbox on Microsoft Windows before 20060402 allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP GET request to TCP port 5225.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hp | Color Laserjet 2500 Toolbox | All versions |
| Hp | Color Laserjet 4600 Toolbox | All versions |
| Hp | Color Laserjet | 4600dn |
| Hp | Color Laserjet | 4600dtn |
| Hp | Color Laserjet | 4600hdn |
| Hp | Color Laserjet 2500 | All versions |
| Hp | Color Laserjet 2500l | All versions |
| Hp | Color Laserjet 2500lse | All versions |
| Hp | Color Laserjet 2500n | All versions |
| Hp | Color Laserjet 2500tn | All versions |
| Hp | Color Laserjet 4600 | All versions |
References
- http://securitytracker.com/id?1015862Exploit, Patch
- http://securitytracker.com/id?1015862Exploit, Patch
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-1654?
How severe is CVE-2006-1654?
How do I fix CVE-2006-1654?
Are you affected by CVE-2006-1654?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
