CVE-2008-2439
TrendMicro OfficeScanNT Listener Traversal Arbitrary File Access
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Directory traversal vulnerability in the UpdateAgent function in TmListen.exe in the OfficeScanNT Listener service in the client in Trend Micro OfficeScan 7.3 Patch 4 build 1367 and other builds before 1372, OfficeScan 8.0 SP1 before build 1222, OfficeScan 8.0 SP1 Patch 1 before build 3087, and Worry-Free Business Security 5.0 before build 1220 allows remote attackers to read arbitrary files via directory traversal sequences in an HTTP request. NOTE: some of these details are obtained from third party information.
Vulnerabilidad de salto de directorio en la función UpdateAgent en TmListen.exe en el servicio OfficeScanNT Listener del cliente de Trend Micro OfficeScan v7.3 Patch 4 build v1367 y otros builds versiones anteriores a v1372, OfficeScan 8.0 SP1 versiones anteriores a build v1222, OfficeScan 8.0 SP1 Patch 1 versiones anteriores a build 3087, y Worry-Free Business Security 5.0 versiones anteriores a build v1220 permite a atacantes remotos leer ficheros de su elección a través de secuencias de salto de directorio en una petición HTTP.
NOTA: algunos de estos detalles han sido obtenidos a partir de la información de terceros.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2008-05-27 CVE Reserved
- 2008-10-03 CVE Published
- 2024-08-07 CVE Updated
- 2024-10-09 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (13)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/archive/1/496970/100/0/threaded | Mailing List | |
http://www.securityfocus.com/bid/31531 | Vdb Entry | |
http://www.securitytracker.com/id?1020975 | Vdb Entry | |
http://www.vupen.com/english/advisories/2008/2711 | Vdb Entry | |
http://www.vupen.com/english/advisories/2008/2712 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/45597 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/secunia_research/2008-39 | 2018-10-11 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Trend Micro Search vendor "Trend Micro" | Officescan Search vendor "Trend Micro" for product "Officescan" | 7.3 Search vendor "Trend Micro" for product "Officescan" and version "7.3" | - |
Affected
| ||||||
Trend Micro Search vendor "Trend Micro" | Officescan Search vendor "Trend Micro" for product "Officescan" | 8.0 Search vendor "Trend Micro" for product "Officescan" and version "8.0" | sp1 |
Affected
| ||||||
Trend Micro Search vendor "Trend Micro" | Officescan Search vendor "Trend Micro" for product "Officescan" | 8.0 Search vendor "Trend Micro" for product "Officescan" and version "8.0" | sp1_patch1 |
Affected
| ||||||
Trend Micro Search vendor "Trend Micro" | Worry Free Business Security Search vendor "Trend Micro" for product "Worry Free Business Security" | 5.0 Search vendor "Trend Micro" for product "Worry Free Business Security" and version "5.0" | - |
Affected
|