Lucene search

K
nvd[email protected]NVD:CVE-2008-5301
HistoryDec 01, 2008 - 5:30 p.m.

CVE-2008-5301

2008-12-0117:30:01
CWE-22
web.nvd.nist.gov
1

6.4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

7.4 High

AI Score

Confidence

High

0.006 Low

EPSS

Percentile

77.9%

Directory traversal vulnerability in the ManageSieve implementation in Dovecot 1.0.15, 1.1, and 1.2 allows remote attackers to read and modify arbitrary .sieve files via a “…” (dot dot) in a script name.

Affected configurations

NVD
Node
dovecotdovecotMatch0.99.13
OR
dovecotdovecotMatch0.99.14
OR
dovecotdovecotMatch1.0
OR
dovecotdovecotMatch1.0.2
OR
dovecotdovecotMatch1.0.3
OR
dovecotdovecotMatch1.0.4
OR
dovecotdovecotMatch1.0.5
OR
dovecotdovecotMatch1.0.6
OR
dovecotdovecotMatch1.0.7
OR
dovecotdovecotMatch1.0.8
OR
dovecotdovecotMatch1.0.9
OR
dovecotdovecotMatch1.0.10
OR
dovecotdovecotMatch1.0.12
OR
dovecotdovecotMatch1.1
OR
dovecotdovecotMatch1.1rc2
OR
dovecotdovecotMatch1.1.0
OR
dovecotdovecotMatch1.1.1
OR
dovecotdovecotMatch1.1.2
OR
dovecotdovecotMatch1.1.3
OR
dovecotdovecotMatch1.1.4
OR
dovecotdovecotMatch1.1.5

6.4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

7.4 High

AI Score

Confidence

High

0.006 Low

EPSS

Percentile

77.9%