VulnerabilityModified
CVE-2008-2286
SQL injection vulnerability in axengine.exe in Symantec Altiris Deployment Solution 6.8.x and 6.9.x before 6.9.176 allows remote attackers to execute arbitrary SQL commands via unspecified string fields in a notification packet.
HIGH 7.5EPSS 32.7%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 32.7%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
SQL injection vulnerability in axengine.exe in Symantec Altiris Deployment Solution 6.8.x and 6.9.x before 6.9.176 allows remote attackers to execute arbitrary SQL commands via unspecified string fields in a notification packet.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 32.68% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- symantec/altiris deployment solution
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=122167472229965&w=2
- http://osvdb.org/show/osvdb/45313
- http://secunia.com/advisories/30261Vendor Advisory
- http://www.exploit-db.com/exploits/29552
- http://www.securityfocus.com/archive/1/492127/100/0/threaded
- http://www.securityfocus.com/archive/1/492229/100/0/threaded
- http://www.securityfocus.com/bid/29198
- http://www.securitytracker.com/id?1020024
- http://www.symantec.com/avcenter/security/Content/2008.05.14a.htmlPatch, Vendor Advisory
- http://www.vupen.com/english/advisories/2008/1542/referencesVendor Advisory
- http://www.zerodayinitiative.com/advisories/ZDI-08-024/
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42436
- http://marc.info/?l=bugtraq&m=122167472229965&w=2
- http://osvdb.org/show/osvdb/45313
- http://secunia.com/advisories/30261Vendor Advisory
- http://www.exploit-db.com/exploits/29552
- http://www.securityfocus.com/archive/1/492127/100/0/threaded
- http://www.securityfocus.com/archive/1/492229/100/0/threaded
- http://www.securityfocus.com/bid/29198
- http://www.securitytracker.com/id?1020024
- http://www.symantec.com/avcenter/security/Content/2008.05.14a.htmlPatch, Vendor Advisory
- http://www.vupen.com/english/advisories/2008/1542/referencesVendor Advisory
- http://www.zerodayinitiative.com/advisories/ZDI-08-024/
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42436
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.