Loading
Directory traversal vulnerability in the IM Server (aka IMserve or IMserver) in Ipswitch Instant Messaging (IM) 2.0.8.1 and earlier allows remote authenticated users to create arbitrary empty files via a .. (dot dot) in the recipient field.
Use CWE-22, Ipswitch vendor hub and Imserver product page to widen CVE-2008-0946 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2007-3959 and CVE-2008-0945 for nearby disclosures in the same product family.