CVE-2008-2286
Symantec Altiris Deployment Solution SQL Injection Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
SQL injection vulnerability in axengine.exe in Symantec Altiris Deployment Solution 6.8.x and 6.9.x before 6.9.176 allows remote attackers to execute arbitrary SQL commands via unspecified string fields in a notification packet.
Vulnerabilidad de inyección SQL en axengine.exe en Symantec Altiris Deployment Solution 6.8.x y 6.9.x en versiones anteriores a 6.9.176 permite a atacantes remotos ejecutar comandos SQL arbitrarios a través de campos de cadena no especificado en un paquete de notificación.
This vulnerability allows attackers to execute arbitrary code on vulnerable installations of Symantec Altiris Deployment Solution. User interaction is not required to exploit this vulnerability.
The specific flaw exists within the axengine.exe process listening by default on TCP port 402. A lack of proper sanitation while parsing requests allows for a remote attacker to inject arbitrary SQL statements into the database. Exploitation of this vulnerability can result in arbitrary code execution under the context of the SYSTEM user.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2008-05-15 CVE Published
- 2008-05-18 CVE Reserved
- 2013-11-13 First Exploit
- 2024-08-07 CVE Updated
- 2024-10-20 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
References (13)
URL | Tag | Source |
---|---|---|
http://osvdb.org/show/osvdb/45313 | Vdb Entry | |
http://www.securityfocus.com/archive/1/492127/100/0/threaded | Mailing List | |
http://www.securityfocus.com/archive/1/492229/100/0/threaded | Mailing List | |
http://www.securityfocus.com/bid/29198 | Vdb Entry | |
http://www.securitytracker.com/id?1020024 | Vdb Entry | |
http://www.zerodayinitiative.com/advisories/ZDI-08-024 | X_refsource_misc | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/42436 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/29552 | 2013-11-13 | |
http://www.exploit-db.com/exploits/29552 | 2024-08-07 |
URL | Date | SRC |
---|---|---|
http://www.symantec.com/avcenter/security/Content/2008.05.14a.html | 2018-10-11 |
URL | Date | SRC |
---|---|---|
http://marc.info/?l=bugtraq&m=122167472229965&w=2 | 2018-10-11 | |
http://secunia.com/advisories/30261 | 2018-10-11 | |
http://www.vupen.com/english/advisories/2008/1542/references | 2018-10-11 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Symantec Search vendor "Symantec" | Altiris Deployment Solution Search vendor "Symantec" for product "Altiris Deployment Solution" | 6.8 Search vendor "Symantec" for product "Altiris Deployment Solution" and version "6.8" | - |
Affected
| ||||||
Symantec Search vendor "Symantec" | Altiris Deployment Solution Search vendor "Symantec" for product "Altiris Deployment Solution" | 6.9 Search vendor "Symantec" for product "Altiris Deployment Solution" and version "6.9" | - |
Affected
|