CVE-2008-0946: Path Traversal
Directory traversal vulnerability in the IM Server (aka IMserve or IMserver) in Ipswitch Instant Messaging (IM) 2.0.8.1 and earlier allows remote authenticated users to create arbitrary empty files via a .. (dot dot) in the recipient field.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-0946?
CVE-2008-0946 has a high severity due to its ability to allow remote authenticated users to exploit directory traversal vulnerabilities.
How do I fix CVE-2008-0946?
To fix CVE-2008-0946, upgrade to a version of Ipswitch Instant Messaging greater than 2.0.8.1.
Who is affected by CVE-2008-0946?
CVE-2008-0946 affects users of Ipswitch Instant Messaging versions 2.0.8.1 and earlier.
What kind of attack can be executed due to CVE-2008-0946?
CVE-2008-0946 allows authenticated attackers to create arbitrary empty files on the server.
Is CVE-2008-0946 exploitable without authentication?
CVE-2008-0946 is not exploitable without authentication, as it requires remote authenticated user privileges.