cbcvebase.
CVE-2008-5301
published 2008-12-01

CVE-2008-5301: Directory traversal vulnerability in the ManageSieve implementation in Dovecot 1.0.15, 1.1, and 1.2 allows remote attackers to read and modify arbitrary .sieve…

PriorityP432medium6.4CVSS 2.0
AVNACLAuNCPIPAN
EPSS
1.83%
76.6th percentile
Directory traversal vulnerability in the ManageSieve implementation in Dovecot 1.0.15, 1.1, and 1.2 allows remote attackers to read and modify arbitrary .sieve files via a ".." (dot dot) in a script name.

Affected

25 ranges
VendorProductVersion rangeFixed in
debiandovecot< dovecot 1:1.0.15-2.3 (bookworm)dovecot 1:1.0.15-2.3 (bookworm)
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot>= 0 < 1:1.0.15-2.31:1.0.15-2.3
dovecotdovecot>= 0 < 1:1.0.15-2.31:1.0.15-2.3
dovecotdovecot>= 0 < 1:1.0.15-2.31:1.0.15-2.3
dovecotdovecot>= 0 < 1:1.0.15-2.31:1.0.15-2.3

CVSS provenance

nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
osv6.4MEDIUM
vendor_ubuntu7.5HIGH
vendor_debian6.4MEDIUM
vendor_redhat6.4MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.