Versant Connection Services Daemon Arbitrary Command Execution

This script is Copyright (C) 2008-2011 Tenable Network Security, Inc.


Synopsis :

The remote database service allows execution of arbitrary commands.

Description :

The version of the Versant Object Database installed on the remote
host accepts input supplied by the client and uses it to launch needed
programs or locate database files. An unauthenticated, remote attacker
can leverage this issue to execute arbitrary commands on the affected
host subject to the privileges under which the service operates, which
under Windows is SYSTEM.

See also :

http://aluigi.altervista.org/adv/versantcmd-adv.txt
http://archives.neohapsis.com/archives/fulldisclosure/2008-03/0036.html

Solution :

Unknown at this time.

Risk factor :

Critical / CVSS Base Score : 10.0
(CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS Temporal Score : 9.0
(CVSS2#E:POC/RL:U/RC:ND)
Public Exploit Available : true

Family: Gain a shell remotely

Nessus Plugin ID: 31419 ()

Bugtraq ID: 28097

CVE ID: CVE-2008-1319