CVE-2008-4397
60Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 81%
from disclosure to weapon563 days
Published on NVDOct 14
1st PoC+563d
metasploitOct 9
exploitation probability
81%top 1% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Directory traversal vulnerability in the RPC interface (asdbapi.dll) in CA ARCserve Backup (formerly BrightStor ARCserve Backup) r11.1 through r12.0 allows remote attackers to execute arbitrary commands via a .. (dot dot) in an RPC call with opnum 0x10A.
Affected products
n/a · n/apublic PoCs found — 1
exploitdbwww.exploit-db.com/exploits/16404unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://secunia.com/advisories/32220http://securityreason.com/securityalert/4412https://exchange.xforce.ibmcloud.com/vulnerabilities/45774https://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=188143http://www.securityfocus.com/archive/1/497218http://www.securityfocus.com/archive/1/497281/100/0/threadedhttp://www.securityfocus.com/bid/31684http://www.securitytracker.com/id?1021032http://www.vupen.com/english/advisories/2008/2777