Unrated severityNVD Advisory· Published Jan 27, 2009· Updated Apr 23, 2026
CVE-2009-0288
CVE-2009-0288
Description
Directory traversal vulnerability in k23productions TFTPUtil GUI 1.2.0 and 1.3.0 allows remote attackers to read arbitrary files outside the TFTP root directory via directory traversal sequences in a GET request.
Affected products
2cpe:2.3:a:windows_tftp_utility:tftputil:1.2.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:windows_tftp_utility:tftputil:1.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:windows_tftp_utility:tftputil:1.3.0:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- sourceforge.net/forum/forum.phpnvdPatch
- www.securityfocus.com/bid/33287nvdPatch
- secunia.com/advisories/33561nvdVendor Advisory
- www.princeofnigeria.org/blogs/index.php/2009/01/14/tftputil-gui-tftp-directory-traversalnvdURL Repurposed
- www.securityfocus.com/archive/1/500106/100/0/threadednvd
- exchange.xforce.ibmcloud.com/vulnerabilities/48019nvd
News mentions
0No linked articles in our index yet.