CVE-2008-0457 EXPLOIT
10.0
HIGH · CVSS 2.0 · EPSS 11.9% (pctl 96)
Patch early
A public exploit exists.
Description
Unrestricted file upload vulnerability in the FileUpload class running on the Symantec LiveState Apache Tomcat server, as used by Symantec Backup Exec System Recovery Manager 7.0 and 7.0.1, allows remote attackers to upload and execute arbitrary JSP files via unknown vectors.
Scoring
| CVSS | 10.0 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
| EPSS | 11.86% — more likely to be exploited than 96% of all CVEs |
| Weakness | CWE-20 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2008-02-07 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| symantec | backupexec system recovery |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Backup Exec System Recovery Manager 7.0.1 - Arbitrary File Upload | 2008-02-07 |
| exploit-db | Symantec Backup Exec System Recovery Manager 7.0 - FileUpload Class Unauthorized File Upload | 2007-01-05 |
References
- http://secunia.com/advisories/28787
- http://seer.entsupport.symantec.com/docs/297171.htm
- http://www.securityfocus.com/archive/1/487688/100/0/threaded
- http://www.securityfocus.com/bid/27487
- http://www.securitytracker.com/id?1019303
- http://www.symantec.com/avcenter/security/Content/2008.02.04.html
- http://www.vupen.com/english/advisories/2008/0413
- http://www.zerodayinitiative.com/advisories/ZDI-08-003.html
- https://www.exploit-db.com/exploits/5078
- http://secunia.com/advisories/28787
- http://seer.entsupport.symantec.com/docs/297171.htm
- http://www.securityfocus.com/archive/1/487688/100/0/threaded
- http://www.securityfocus.com/bid/27487
- http://www.securitytracker.com/id?1019303
- http://www.symantec.com/avcenter/security/Content/2008.02.04.html
- http://www.vupen.com/english/advisories/2008/0413
- http://www.zerodayinitiative.com/advisories/ZDI-08-003.html
- https://www.exploit-db.com/exploits/5078
→ the Explorer · watch your stack · NVD