peter bassill · operator
$ cve CVE-2007-2639 JSON

CVE-2007-2639 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 3.6% (pctl 89)

Patch early

A public exploit exists.

Description

Directory traversal vulnerability in TFTPdWin 0.4.2 allows remote attackers to read or modify arbitrary files outside the TFTP root via unspecified vectors.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS3.62% — more likely to be exploited than 89% of all CVEs
On CISA KEVno
Public exploityes
Published2007-05-13
Last modified2026-06-16

Affected (1)

VendorProduct
prosysinfotftp server tftpdwin

Public exploits

SourceTitleDate
exploit-dbTFTP Server TFTPDWin 0.4.2 - Directory Traversal2007-05-11

References

→ the Explorer  ·  watch your stack  ·  NVD