CVE-2008-0946
Estado: ModificadaMedia (4.9)—
Directory traversal vulnerability in the IM Server (aka IMserve or IMserver) in Ipswitch Instant Messaging (IM) 2.0.8.1 and earlier allows remote authenticated users to create arbitrary empty files via a .. (dot dot) in the recipient field.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:M/Au:S/C:P/I:P/A:N
- Puntuación base: 4.9
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 3.55%
- Percentil entre todas las CVEs puntuadas: 89
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- CWE-22
Referencias
- http://aluigi.altervista.org/adv/ipsimene-adv.txt
- http://aluigi.org/poc/ipsimene.zip
- http://securityreason.com/securityalert/3697
- http://www.securityfocus.com/archive/1/487748/100/200/threaded
- http://www.securityfocus.com/bid/27677
- http://aluigi.altervista.org/adv/ipsimene-adv.txt
- http://aluigi.org/poc/ipsimene.zip
- http://securityreason.com/securityalert/3697
- http://www.securityfocus.com/archive/1/487748/100/200/threaded
- http://www.securityfocus.com/bid/27677
JSON original (NVD)
Mostrar
{
"id": "CVE-2008-0946",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.9,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:S/C:P/I:P/A:N",
"authentication": "SINGLE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 4.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 6.8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2008-02-25T21:44:00.000",
"references": [
{
"url": "http://aluigi.altervista.org/adv/ipsimene-adv.txt",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://aluigi.org/poc/ipsimene.zip",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://securityreason.com/securityalert/3697",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/487748/100/200/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/27677",
"source": "cve@mitre.org"
},
{
"url": "http://aluigi.altervista.org/adv/ipsimene-adv.txt",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://aluigi.org/poc/ipsimene.zip",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://securityreason.com/securityalert/3697",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/487748/100/200/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/27677",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-22"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Directory traversal vulnerability in the IM Server (aka IMserve or IMserver) in Ipswitch Instant Messaging (IM) 2.0.8.1 and earlier allows remote authenticated users to create arbitrary empty files via a .. (dot dot) in the recipient field."
},
{
"lang": "es",
"value": "Vulnerabilidad de salto de directorio en IM Server (también conocido como IMserve o IMserver) de Ipswitch Instant Messaging (IM) 2.0.8.1 y anteriores permite a usuarios autentificados remotamente crear archivos vacíos de su elección a través de .. (punto punto) en el campo receptor."
}
],
"lastModified": "2026-06-16T22:50:39.603",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:ipswitch:imserver:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "37107C28-9B74-4C67-8A0D-E746647C34FF",
"versionEndIncluding": "2.0.8.1"
},
{
"criteria": "cpe:2.3:a:ipswitch:instant_messaging:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "063110BD-F65A-48F8-BD75-54CA1E370D24",
"versionEndIncluding": "2.0.8.1"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}