Vulnerability record · CVE-2008-1117 · published 14 March 2008
CVE-2008-1117: Timbuktu Pro Notes directory traversal allows arbitrary file upload
Netopia · Timbuktu Pro
The Notes (instant message) feature in tb2ftp.dll in Timbuktu Pro 8.6.5 for Windows (and possibly 8.7 for Mac OS X) fails to properly sanitize destination filenames, allowing a backslash followed by ../ sequences to escape the intended upload directory. This is an incomplete fix for CVE-2007-4220, so the original traversal weakness remains reachable. Because the flaw permits writing files to arbitrary paths, it can lead to code execution when a file is placed in a Startup folder.
Description
Directory traversal vulnerability in the Notes (aka Flash Notes or instant messages) feature in tb2ftp.dll in Timbuktu Pro 8.6.5 for Windows, and possibly 8.7 for Mac OS X, allows remote attackers to upload files to arbitrary locations via a destination filename with a \ (backslash) character followed by ../ (dot dot slash) sequences. NOTE: this can be leveraged for code execution by writing to a Startup folder. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2007-4220.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 10.0 with network reachability, no authentication, and public exploit code enabling remote code execution makes this a critical risk.
What it is
The Notes (instant message) feature in tb2ftp.dll in Timbuktu Pro 8.6.5 for Windows (and possibly 8.7 for Mac OS X) fails to properly sanitize destination filenames, allowing a backslash followed by ../ sequences to escape the intended upload directory. This is an incomplete fix for CVE-2007-4220, so the original traversal weakness remains reachable. Because the flaw permits writing files to arbitrary paths, it can lead to code execution when a file is placed in a Startup folder.
Impact
A remote attacker can write files to any location the Timbuktu Pro service can access, including Startup folders, which enables arbitrary code execution under the service account. This gives full compromise of the affected host.
Attack surface
The vulnerability is reachable over the network through the Notes/instant message file transfer functionality in tb2ftp.dll. The CVSS vector (AV:N/AC:L/Au:N) indicates no authentication and no user interaction are required.
Exploitation
Public exploit code is referenced (Exploit-DB entries and an aluigi PoC tagged Exploit), and EPSS is 0.69473 (99.3rd percentile), indicating high likelihood of exploitation. The CVE is not listed in CISA KEV.
What to do
- Apply the vendor fix for Timbuktu Pro or upgrade to a version that fully addresses the incomplete CVE-2007-4220 fix; if no patch is available, remove or disable the product.
- Block or restrict network access to the Timbuktu Pro Notes/file transfer service (tb2ftp.dll) to trusted hosts only.
- Run the Timbuktu Pro service with least privilege and ensure its account cannot write to Startup folders or other sensitive directories.
- Monitor and restrict file writes from the service account to unexpected paths, especially Startup folders.
Detection
- Monitor file creation events in Startup folders and other sensitive directories for files written by the Timbuktu Pro service account.
- Inspect network traffic to the Timbuktu Pro file transfer port for filenames containing backslash followed by ../ sequences.
- Review Timbuktu Pro logs for Notes/instant message file transfers with unusual destination paths.
- Alert on unexpected executable or script files appearing in user or system Startup locations.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2008-1117 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2008-1117), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.