4.9
CVSSv2

CVE-2008-0946

Published: 25/02/2008 Updated: 15/10/2018
CVSS v2 Base Score: 4.9 | Impact Score: 4.9 | Exploitability Score: 6.8
VMScore: 436
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:N

Vulnerability Summary

Directory traversal vulnerability in the IM Server (aka IMserve or IMserver) in Ipswitch Instant Messaging (IM) 2.0.8.1 and previous versions allows remote authenticated users to create arbitrary empty files via a .. (dot dot) in the recipient field.

Vulnerable Product Search on Vulmon Subscribe to Product

ipswitch imserver

ipswitch instant messaging