CVE-2008-4677 describes a vulnerability in the Netrw Plugin (autoload/netrw.vim) for Vim versions 7.1 and 7.2. This flaw causes the plugin to improperly store and reuse FTP credentials across different hosts, potentially exposing sensitive information to malicious FTP servers. The vulnerability has a CVSS score of 4.3, indicating a medium severity. An attacker could exploit this remotely with medium complexity, leading to a partial compromise of confidentiality (C:P) by logging usernames and passwords. There is no evidence of active exploitation, and no public exploit code is available through Metasploit, Nuclei, or ExploitDB. The vulnerability has received minimal community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
109CPE matchmatch criteria | cpe:2.3:a:vim:netrw:109:*:*:*:*:*:*:* | ||
110CPE matchmatch criteria | cpe:2.3:a:vim:netrw:110:*:*:*:*:*:*:* | ||
111CPE matchmatch criteria | cpe:2.3:a:vim:netrw:111:*:*:*:*:*:*:* | ||
112CPE matchmatch criteria | cpe:2.3:a:vim:netrw:112:*:*:*:*:*:*:* | ||
113CPE matchmatch criteria | cpe:2.3:a:vim:netrw:113:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.