Vulnerability Name: | CVE-2008-0457 (CCN-40260) | ||||||||
Assigned: | 2008-02-04 | ||||||||
Published: | 2008-02-04 | ||||||||
Updated: | 2018-10-15 | ||||||||
Summary: | Unrestricted file upload vulnerability in the FileUpload class running on the Symantec LiveState Apache Tomcat server, as used by Symantec Backup Exec System Recovery Manager 7.0 and 7.0.1, allows remote attackers to upload and execute arbitrary JSP files via unknown vectors. | ||||||||
CVSS v3 Severity: | 10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C) 7.8 High (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:POC/RL:OF/RC:C)
7.8 High (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:POC/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-20 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2008-0457 Source: CCN Type: SA28787 Symantec Backup Exec System Recovery Manager File Upload Vulnerability Source: SECUNIA Type: Vendor Advisory 28787 Source: CCN Type: SECTRACK ID: 1019303 Symantec BackupExec System Recovery Manager Lets Remote Users Upload Arbitrary Files and Execute Arbitrary Code Source: CONFIRM Type: Patch http://seer.entsupport.symantec.com/docs/297171.htm Source: CCN Type: OSVDB ID: 41149 Symantec Backup Exec System Recovery Manager Arbitrary File Upload / Execution Source: BUGTRAQ Type: UNKNOWN 20080206 ZDI-08-003: Symantec Backup Exec Remote File Upload Vulnerability Source: BID Type: Exploit 27487 Source: CCN Type: BID-27487 Symantec Backup Exec System Recovery Manager FileUpload Class Unauthorized File Upload Vulnerability Source: SECTRACK Type: UNKNOWN 1019303 Source: CCN Type: SYM08-001 Symantec Backup Exec System Recovery Manager - Unauthorized File Upload Source: CONFIRM Type: Patch http://www.symantec.com/avcenter/security/Content/2008.02.04.html Source: CCN Type: Symantec Web site AntiVirus, Anti-Spyware, Endpoint Security, Backup, Storage, and Compliance Solutions - Symantec Corp Source: VUPEN Type: Vendor Advisory ADV-2008-0413 Source: MISC Type: UNKNOWN http://www.zerodayinitiative.com/advisories/ZDI-08-003.html Source: XF Type: UNKNOWN recoverymanager-fileuploadclass-file-upload(40260) Source: EXPLOIT-DB Type: UNKNOWN 5078 Source: CCN Type: ZDI-08-003 Symantec Backup Exec Remote File Upload Vulnerability | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |