peter bassill · operator
$ cve CVE-2008-0464 JSON

CVE-2008-0464 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 3.3% (pctl 88)

Patch early

A public exploit exists.

Description

Directory traversal vulnerability in archiv.cgi in absofort aconon Mail 2007 Enterprise SQL 11.7.0 and Mail 2004 Enterprise SQL 11.5.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the template parameter.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS3.32% — more likely to be exploited than 88% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploityes
Published2008-01-25
Last modified2026-06-16

Affected (1)

VendorProduct
absofortaconon mail enterprise sql

Public exploits

SourceTitleDate
exploit-dbAconon Mail 2004 - Directory Traversal2008-01-23

References

→ the Explorer  ·  watch your stack  ·  NVD