peter bassill · operator
$ cve CVE-2008-2286 JSON

CVE-2008-2286 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 32.7% (pctl 98)

Patch early

A public exploit exists.

Description

SQL injection vulnerability in axengine.exe in Symantec Altiris Deployment Solution 6.8.x and 6.9.x before 6.9.176 allows remote attackers to execute arbitrary SQL commands via unspecified string fields in a notification packet.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS32.68% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploityes
Published2008-05-18
Last modified2026-06-16

Affected (1)

VendorProduct
symantecaltiris deployment solution

Public exploits

SourceTitleDate
exploit-dbSymantec Altiris DS - SQL Injection (Metasploit)2013-11-13

References

→ the Explorer  ·  watch your stack  ·  NVD