Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2008-4677

autoload/netrw.vim (aka the Netrw Plugin) 109, 131, and other versions before 133k for Vim 7.1.266, other 7.1 versions, and 7.2 stores credentials for an FTP session, and sends those credentials when attempting to establish subsequent FTP sessions to servers on different hosts, which allows remote FTP servers to obtain sensitive information in opportunistic circumstances by logging usernames and passwords. NOTE: the upstream vendor disputes a vector involving different ports on the same host, stating "I'm assuming that they're using the same id and password on that unchanged hostname, deliberately."
Exploit prediction scoring system (EPSS) score
EPSS Score 0.009
EPSS Ranking 74.8%
CVSS Severity
CVSS v2 Score 4.3
References
Products affected by CVE-2008-4677
  • Vim » Netrw » Version: 109
    cpe:2.3:a:vim:netrw:109
  • Vim » Netrw » Version: 110
    cpe:2.3:a:vim:netrw:110
  • Vim » Netrw » Version: 111
    cpe:2.3:a:vim:netrw:111
  • Vim » Netrw » Version: 112
    cpe:2.3:a:vim:netrw:112
  • Vim » Netrw » Version: 113
    cpe:2.3:a:vim:netrw:113
  • Vim » Netrw » Version: 114
    cpe:2.3:a:vim:netrw:114
  • Vim » Netrw » Version: 115
    cpe:2.3:a:vim:netrw:115
  • Vim » Netrw » Version: 116
    cpe:2.3:a:vim:netrw:116
  • Vim » Netrw » Version: 118
    cpe:2.3:a:vim:netrw:118
  • Vim » Netrw » Version: 120
    cpe:2.3:a:vim:netrw:120
  • Vim » Netrw » Version: 121
    cpe:2.3:a:vim:netrw:121
  • Vim » Netrw » Version: 122
    cpe:2.3:a:vim:netrw:122
  • Vim » Netrw » Version: 123
    cpe:2.3:a:vim:netrw:123
  • Vim » Netrw » Version: 128
    cpe:2.3:a:vim:netrw:128
  • Vim » Netrw » Version: 131
    cpe:2.3:a:vim:netrw:131
  • Vim » Vim » Version: 7.1
    cpe:2.3:a:vim:vim:7.1
  • Vim » Vim » Version: 7.1.266
    cpe:2.3:a:vim:vim:7.1.266
  • Vim » Vim » Version: 7.2
    cpe:2.3:a:vim:vim:7.2


Contact Us

Shodan ® - All rights reserved