Vulnerability CVE-2008-1319


Published: 2008-03-13   Modified: 2012-02-12

Description:
Untrusted search path and argument injection vulnerability in the VersantD service in Versant Object Database 7.0.1.3 and earlier, as used in Borland CaliberRM and probably other products, allows remote attackers to execute arbitrary commands via a request to TCP port 5019 with a modified VERSANT_ROOT field.

See advisories in our WLB2 database:
Topic
Author
Date
High
Arbitrary commands execution in Versant Object Database 7.0.1.3
Luigi Auriemma
13.03.2008

Type:

CWE-Other

CVSS2 => (AV:N/AC:M/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
9.3/10
10/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
Versant -> Versant object database 

 References:
http://aluigi.altervista.org/adv/versantcmd-adv.txt
http://marc.info/?l=bugtraq&m=120468784112145&w=2
http://securityreason.com/securityalert/3738
http://www.securityfocus.com/archive/1/489139/100/0/threaded
http://www.securityfocus.com/bid/28097
http://www.vupen.com/english/advisories/2008/0764/references
https://exchange.xforce.ibmcloud.com/vulnerabilities/40997
https://www.exploit-db.com/exploits/5213

Copyright 2024, cxsecurity.com

 

Back to Top