CVE-2008-2044
Estado: ModificadaAlta (7.5)—💥 Exploit
includes/library.php in netOffice Dwins 1.3 p2 compares the demoSession variable to the 'true' string literal instead of the true boolean literal, which allows remote attackers to bypass authentication and execute arbitrary code by setting this variable to 1, as demonstrated by uploading a PHP script via an add action to projects_site/uploadfile.php.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 11%
- Percentil entre todas las CVEs puntuadas: 96
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
💥 Exploits públicos
Hay código de explotación o plantillas de detección públicos. No es lo mismo que explotación activa confirmada (KEV), pero aumenta el riesgo: parchee con prioridad.
- Publicado en Exploit-DB · NetOffice Dwins 1.3 - Authentication Bypass / Arbitrary File Upload (29/2/2008)
Tecnologías afectadas (1)
CWE
- CWE-94
Referencias
- http://netofficedwins.sourceforge.net/modules/news/article.php?storyid=47
- http://secunia.com/advisories/29193
- http://securityreason.com/securityalert/3845
- http://sourceforge.net/forum/forum.php?forum_id=814851
- http://www.securityfocus.com/archive/1/488958
- http://www.securityfocus.com/archive/1/491542/100/0/threaded
- http://www.securityfocus.com/bid/28051
- http://netofficedwins.sourceforge.net/modules/news/article.php?storyid=47
- http://secunia.com/advisories/29193
- http://securityreason.com/securityalert/3845
- http://sourceforge.net/forum/forum.php?forum_id=814851
- http://www.securityfocus.com/archive/1/488958
- http://www.securityfocus.com/archive/1/491542/100/0/threaded
- http://www.securityfocus.com/bid/28051
JSON original (NVD)
Mostrar
{
"id": "CVE-2008-2044",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": true,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2008-05-01T19:05:00.000",
"references": [
{
"url": "http://netofficedwins.sourceforge.net/modules/news/article.php?storyid=47",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/29193",
"source": "cve@mitre.org"
},
{
"url": "http://securityreason.com/securityalert/3845",
"source": "cve@mitre.org"
},
{
"url": "http://sourceforge.net/forum/forum.php?forum_id=814851",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/488958",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/491542/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/28051",
"source": "cve@mitre.org"
},
{
"url": "http://netofficedwins.sourceforge.net/modules/news/article.php?storyid=47",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/29193",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://securityreason.com/securityalert/3845",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://sourceforge.net/forum/forum.php?forum_id=814851",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/488958",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/491542/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/28051",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-94"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "includes/library.php in netOffice Dwins 1.3 p2 compares the demoSession variable to the 'true' string literal instead of the true boolean literal, which allows remote attackers to bypass authentication and execute arbitrary code by setting this variable to 1, as demonstrated by uploading a PHP script via an add action to projects_site/uploadfile.php."
},
{
"lang": "es",
"value": "includes/library.php en netOffice Dwins 1.3 p2 compara la variable demoSession con la cadena literal \"true\" en lugar de compararla con el valor lógico true, lo que permite a los atacantes remotos saltarse la autenticación y ejecutar código arbitrario fijando el valor de la variable a 1, como se demuestra subiendo un script PHP a través de la acción add a projects_site/iploadfile.php."
}
],
"lastModified": "2026-06-16T22:52:59.493",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:netoffice:dwins:1.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "034660B1-1064-4657-A421-7BF4734A573A"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}