peter bassill · operator
$ cve CVE-2008-1319 JSON

CVE-2008-1319 EXPLOIT

9.3
HIGH · CVSS 2.0 · EPSS 4.8% (pctl 92)

Patch early

A public exploit exists.

Description

Untrusted search path and argument injection vulnerability in the VersantD service in Versant Object Database 7.0.1.3 and earlier, as used in Borland CaliberRM and probably other products, allows remote attackers to execute arbitrary commands via a request to TCP port 5019 with a modified VERSANT_ROOT field.

Scoring

CVSS9.3 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS4.8% — more likely to be exploited than 92% of all CVEs
On CISA KEVno
Public exploityes
Published2008-03-13
Last modified2026-06-16

Affected (1)

VendorProduct
versantversant object database

Public exploits

SourceTitleDate
exploit-dbVersant Object Database 7.0.1.3 - Commands Execution2008-03-04

References

→ the Explorer  ·  watch your stack  ·  NVD