10
CVSSv2

CVE-2008-4397

Published: 14/10/2008 Updated: 09/04/2021
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Directory traversal vulnerability in the RPC interface (asdbapi.dll) in CA ARCserve Backup (formerly BrightStor ARCserve Backup) r11.1 through r12.0 allows remote malicious users to execute arbitrary commands via a .. (dot dot) in an RPC call with opnum 0x10A.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

broadcom server protection suite r2

broadcom business protection suite r2

ca arcserve backup r11.1

ca arcserve backup r11.5

broadcom arcserve backup r12.0

ca business protection suite r2

Exploits

## # $Id: ca_arcserve_342rb 9179 2010-04-30 08:40:19Z jduck $ ## ## # This file is part of the Metasploit Framework and may be subject to # redistribution and commercial restrictions Please see the Metasploit # Framework web site for more information on licensing and terms of use # metasploitcom/framework/ ## require 'msf/core' class ...
CA BrightStor ARCServe BackUp is an overall data backup solution The RPC interface of CA BrightStor ARCServe BackUp does not handle user's input exactly that allows anonymous attacker to inject any command, a remote code execution attack may achieved through this way Details are provided CA BrightStor ARCServe BackUp version R115 is affected ...