CVE-2008-1319
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
13/03/2008
Last modified:
09/04/2025
Description
Untrusted search path and argument injection vulnerability in the VersantD service in Versant Object Database 7.0.1.3 and earlier, as used in Borland CaliberRM and probably other products, allows remote attackers to execute arbitrary commands via a request to TCP port 5019 with a modified VERSANT_ROOT field.
Impact
Base Score 2.0
9.30
Severity 2.0
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:versant:versant_object_database:*:*:*:*:*:*:*:* | 7.0.1.3 (including) | |
cpe:2.3:a:versant:versant_object_database:7.0.1:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://aluigi.altervista.org/adv/versantcmd-adv.txt
- http://marc.info/?l=bugtraq&m=120468784112145&w=2
- http://secunia.com/advisories/29230
- http://securityreason.com/securityalert/3738
- http://www.securityfocus.com/archive/1/489139/100/0/threaded
- http://www.securityfocus.com/bid/28097
- http://www.vupen.com/english/advisories/2008/0764/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/40997
- https://www.exploit-db.com/exploits/5213
- http://aluigi.altervista.org/adv/versantcmd-adv.txt
- http://marc.info/?l=bugtraq&m=120468784112145&w=2
- http://secunia.com/advisories/29230
- http://securityreason.com/securityalert/3738
- http://www.securityfocus.com/archive/1/489139/100/0/threaded
- http://www.securityfocus.com/bid/28097
- http://www.vupen.com/english/advisories/2008/0764/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/40997
- https://www.exploit-db.com/exploits/5213