PT-2008-2089 · Symantec+1 · Symantec Backup Exec System Recovery Manager+1

Titon

·

Publicado

2008-02-07

·

Atualizado

2018-10-15

·

CVE-2008-0457

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Symantec Backup Exec System Recovery Manager versions 7.0 through 7.0.1
Description The issue is related to an unrestricted file upload vulnerability in the FileUpload class of the Symantec LiveState Apache Tomcat server. This vulnerability allows remote attackers to upload and execute arbitrary JSP files.
Recommendations For Symantec Backup Exec System Recovery Manager versions 7.0 through 7.0.1, consider restricting access to the FileUpload class as a temporary workaround until a patch is available.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-0457

Produtos afetados

Apache Tomcat
Symantec Backup Exec System Recovery Manager