peter bassill · operator
$ cve CVE-2008-1117 JSON

CVE-2008-1117 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 69.5% (pctl 99)

Patch early

A public exploit exists.

Description

Directory traversal vulnerability in the Notes (aka Flash Notes or instant messages) feature in tb2ftp.dll in Timbuktu Pro 8.6.5 for Windows, and possibly 8.7 for Mac OS X, allows remote attackers to upload files to arbitrary locations via a destination filename with a \ (backslash) character followed by ../ (dot dot slash) sequences. NOTE: this can be leveraged for code execution by writing to a Startup folder. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2007-4220.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS69.47% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploityes
Published2008-03-14
Last modified2026-06-16

Affected (1)

VendorProduct
netopiatimbuktu pro

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD