Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2008-0457

Overview

Vulnerability Score 10.0 10.0
CVE Id CVE-2008-0457
Last Modified 19 May 2011 12:00:00
Published 07 Feb 2008 04:00:00
Confidentiality Impact COMPLETE COMPLETE
Integrity Impact COMPLETE COMPLETE
Availability Impact COMPLETE COMPLETE
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2008-0457

Summary

Unrestricted file upload vulnerability in the FileUpload class running on the Symantec LiveState Apache Tomcat server, as used by Symantec Backup Exec System Recovery Manager 7.0 and 7.0.1, allows remote attackers to upload and execute arbitrary JSP files via unknown vectors.

Vulnerable Systems

Application

  • Symantec Backupexec System Recovery 7.0

  • Symantec Backupexec System Recovery 7.01


References

CONFIRM - http://www.symantec.com/avcenter/security/Content/2008.02.04.html

CONFIRM - http://seer.entsupport.symantec.com/docs/297171.htm

MISC - http://www.zerodayinitiative.com/advisories/ZDI-08-003.html

VUPEN - ADV-2008-0413

SECTRACK - 1019303

BID - 27487

BUGTRAQ - 20080206 ZDI-08-003: Symantec Backup Exec Remote File Upload Vulnerability

MILW0RM - 5078

SECUNIA - 28787


Last Updated: 27 May 2016 10:46:48