CVE-2008-1000 describes a directory traversal vulnerability in the Wiki Server component of Apple Mac OS X 10.5.2 (Leopard). This flaw allows remote authenticated users to write arbitrary files to the server by including ".." sequences in file attachments. With a CVSS score of 8.5, this vulnerability is considered highly severe, indicating a network-based attack with medium complexity, leading to complete compromise of confidentiality, integrity, and availability. The FAUCET Risk Score of 92/100 further emphasizes its critical nature. While not listed in CISA's KEV catalog, an exploit for this vulnerability is publicly available on ExploitDB. Community discussion and media coverage, though limited, suggest some awareness of this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10.5.2CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:10.5.2:*:*:*:*:*:*:* | ||
10.5.2CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x_server:10.5.2:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:S/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.