← Vulnerability feed

Vulnerability record · CVE-2008-1117 · published 14 March 2008

CVE-2008-1117: Timbuktu Pro Notes directory traversal allows arbitrary file upload

Netopia · Timbuktu Pro

The Notes (instant message) feature in tb2ftp.dll in Timbuktu Pro 8.6.5 for Windows (and possibly 8.7 for Mac OS X) fails to properly sanitize destination filenames, allowing a backslash followed by ../ sequences to escape the intended upload directory. This is an incomplete fix for CVE-2007-4220, so the original traversal weakness remains reachable. Because the flaw permits writing files to arbitrary paths, it can lead to code execution when a file is placed in a Startup folder.

10.0 CVSS 2.0 High EPSS 69% · top 0.7% CWE-22 · Path traversal
10.0CVSS 2.0 base score
69%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
24References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Directory traversal vulnerability in the Notes (aka Flash Notes or instant messages) feature in tb2ftp.dll in Timbuktu Pro 8.6.5 for Windows, and possibly 8.7 for Mac OS X, allows remote attackers to upload files to arbitrary locations via a destination filename with a \ (backslash) character followed by ../ (dot dot slash) sequences. NOTE: this can be leveraged for code execution by writing to a Startup folder. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2007-4220.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityCVSS 10.0 with network reachability, no authentication, and public exploit code enabling remote code execution makes this a critical risk.

What it is

The Notes (instant message) feature in tb2ftp.dll in Timbuktu Pro 8.6.5 for Windows (and possibly 8.7 for Mac OS X) fails to properly sanitize destination filenames, allowing a backslash followed by ../ sequences to escape the intended upload directory. This is an incomplete fix for CVE-2007-4220, so the original traversal weakness remains reachable. Because the flaw permits writing files to arbitrary paths, it can lead to code execution when a file is placed in a Startup folder.

Impact

A remote attacker can write files to any location the Timbuktu Pro service can access, including Startup folders, which enables arbitrary code execution under the service account. This gives full compromise of the affected host.

Attack surface

The vulnerability is reachable over the network through the Notes/instant message file transfer functionality in tb2ftp.dll. The CVSS vector (AV:N/AC:L/Au:N) indicates no authentication and no user interaction are required.

Exploitation

Public exploit code is referenced (Exploit-DB entries and an aluigi PoC tagged Exploit), and EPSS is 0.69473 (99.3rd percentile), indicating high likelihood of exploitation. The CVE is not listed in CISA KEV.

What to do

  • Apply the vendor fix for Timbuktu Pro or upgrade to a version that fully addresses the incomplete CVE-2007-4220 fix; if no patch is available, remove or disable the product.
  • Block or restrict network access to the Timbuktu Pro Notes/file transfer service (tb2ftp.dll) to trusted hosts only.
  • Run the Timbuktu Pro service with least privilege and ensure its account cannot write to Startup folders or other sensitive directories.
  • Monitor and restrict file writes from the service account to unexpected paths, especially Startup folders.

Detection

  • Monitor file creation events in Startup folders and other sensitive directories for files written by the Timbuktu Pro service account.
  • Inspect network traffic to the Timbuktu Pro file transfer port for filenames containing backslash followed by ../ sequences.
  • Review Timbuktu Pro logs for Notes/instant message file transfers with unusual destination paths.
  • Alert on unexpected executable or script files appearing in user or system Startup locations.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2008-1117 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2008-1118Netopia timbuktu pro improper input validation vulnerabilityTimbuktu Pro 8.6.5 for Windows, and possibly 8.7 for Mac OS X, does not perform input validation before logging information fields taken from packets…EPSS 2.9%5.0CVE-2008-1337Netopia timbuktu pro improper input validation vulnerabilityThe instant message service in Timbuktu Pro 8.6.5 RC 229 and earlier for Windows allows remote attackers to cause (1) a denial of service (daemon cra…EPSS 1.7%5.0CVE-2002-0135Netopia timbuktu pro vulnerabilityNetopia Timbuktu Pro 6.0.1 and earlier allows remote attackers to cause a denial of service (crash) via a series of connections to one of the ports (…EPSS 3.2%5.0CVE-2000-0142Netopia timbuktu pro vulnerabilityThe authentication protocol in Timbuktu Pro 2.0b650 allows remote attackers to cause a denial of service via connections to port 407 and 1417.EPSS 8.0%5.0CVE-2000-0086Netopia timbuktu pro vulnerabilityNetopia Timbuktu Pro sends user IDs and passwords in cleartext, which allows remote attackers to obtain them via sniffing.EPSS 1.4%9.8CVE-2026-93616Checkpoint multi-domain security management path traversal vulnerabilityA directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Managem…KEVEPSS 20%10.0CVE-2026-85706GitLab CE/EE repository commits API path traversal allows unauthenticated file readGitLab CE/EE contains improper path confinement and missing authentication enforcement in the repository commits API, allowing an unauthenticated use…KEVEPSS 91%analysed5.3CVE-2026-66384JFrog Artifactory path traversal in Docker cache pathAn authenticated user can write data outside the intended Docker cache path under specific remote-repository conditions in JFrog Artifactory. The fla…KEVEPSS 0.66%analysed

Source: NIST National Vulnerability Database (record CVE-2008-1117), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.