CVE-2008-0946
25.02.2008, 21:44
Directory traversal vulnerability in the IM Server (aka IMserve or IMserver) in Ipswitch Instant Messaging (IM) 2.0.8.1 and earlier allows remote authenticated users to create arbitrary empty files via a .. (dot dot) in the recipient field.
Vendor | Product | Version |
---|---|---|
ipswitch | imserver | 𝑥 ≤ 2.0.8.1 |
ipswitch | instant_messaging | 𝑥 ≤ 2.0.8.1 |
𝑥
= Vulnerable software versions
References