Directory traversal vulnerability in the IM Server (aka IMserve or IMserver) in Ipswitch Instant Messaging (IM) 2.0.8.1 and earlier allows remote authenticated users to create arbitrary empty files via a .. (dot dot) in the recipient field.
| Software | From | Fixed in |
|---|---|---|
| ipswitch / imserver | - | 2.0.8.1.x |
| ipswitch / instant_messaging | - | 2.0.8.1.x |