AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2008-1117

HIGH · CVSS 10 EPSS 69.47% Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2008-03-14 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
code execution
External Security References

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2008-1117
Severity
HIGH
CVSS
10
EPSS
69.47%
Windows

Original NVD Description

Directory traversal vulnerability in the Notes (aka Flash Notes or instant messages) feature in tb2ftp.dll in Timbuktu Pro 8.6.5 for Windows, and possibly 8.7 for Mac OS X, allows remote attackers to upload files to arbitrary locations via a destination filename with a \ (backslash) character followed by ../ (dot dot slash) sequences. NOTE: this can be leveraged for code execution by writing to a Startup folder. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2007-4220.