peter bassill · operator
$ cve CVE-2008-1118 JSON

CVE-2008-1118 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 2.9% (pctl 87)

Patch early

A public exploit exists.

Description

Timbuktu Pro 8.6.5 for Windows, and possibly 8.7 for Mac OS X, does not perform input validation before logging information fields taken from packets from a remote peer, which allows remote attackers to generate crafted log entries, and possibly avoid detection of attacks, via modified (1) computer name, (2) user name, and (3) IP address fields.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS2.94% — more likely to be exploited than 87% of all CVEs
WeaknessCWE-20
On CISA KEVno
Public exploityes
Published2008-03-14
Last modified2026-06-16

Affected (1)

VendorProduct
netopiatimbuktu pro

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD