CVE-2008-1118 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 2.9% (pctl 87)
Patch early
A public exploit exists.
Description
Timbuktu Pro 8.6.5 for Windows, and possibly 8.7 for Mac OS X, does not perform input validation before logging information fields taken from packets from a remote peer, which allows remote attackers to generate crafted log entries, and possibly avoid detection of attacks, via modified (1) computer name, (2) user name, and (3) IP address fields.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 2.94% — more likely to be exploited than 87% of all CVEs |
| Weakness | CWE-20 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2008-03-14 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| netopia | timbuktu pro |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Motorola Timbuktu Pro 8.6.5/8.7 - Directory Traversal / Log Injection | 2008-03-11 |
References
- http://secunia.com/advisories/29316
- http://securityreason.com/securityalert/3742
- http://www.coresecurity.com/?action=item&id=2166
- http://www.securityfocus.com/archive/1/489414/100/0/threaded
- http://www.securityfocus.com/bid/28081
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41330
- https://www.exploit-db.com/exploits/5238
- http://secunia.com/advisories/29316
- http://securityreason.com/securityalert/3742
- http://www.coresecurity.com/?action=item&id=2166
- http://www.securityfocus.com/archive/1/489414/100/0/threaded
- http://www.securityfocus.com/bid/28081
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41330
- https://www.exploit-db.com/exploits/5238
→ the Explorer · watch your stack · NVD