CVE-2008-0464 EXPLOIT
5.0
MEDIUM · CVSS 2.0 · EPSS 3.3% (pctl 88)
Patch early
A public exploit exists.
Description
Directory traversal vulnerability in archiv.cgi in absofort aconon Mail 2007 Enterprise SQL 11.7.0 and Mail 2004 Enterprise SQL 11.5.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the template parameter.
Scoring
| CVSS | 5.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
| EPSS | 3.32% — more likely to be exploited than 88% of all CVEs |
| Weakness | CWE-22 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2008-01-25 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| absofort | aconon mail enterprise sql |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Aconon Mail 2004 - Directory Traversal | 2008-01-23 |
References
- http://burnachurch.com/67/directory-traversal-luecke-in-aconon-mail/
- http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059856.html
- http://secunia.com/advisories/28617
- http://www.securityfocus.com/bid/27427
- http://www.vupen.com/english/advisories/2008/0310
- https://www.exploit-db.com/exploits/4977
- http://burnachurch.com/67/directory-traversal-luecke-in-aconon-mail/
- http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059856.html
- http://secunia.com/advisories/28617
- http://www.securityfocus.com/bid/27427
- http://www.vupen.com/english/advisories/2008/0310
- https://www.exploit-db.com/exploits/4977
→ the Explorer · watch your stack · NVD