Versant Connection Services Daemon Arbitrary Command Execution

This script is Copyright (C) 2008-2016 Tenable Network Security, Inc.

Synopsis :

The remote database service allows execution of arbitrary commands.

Description :

The version of the Versant Object Database installed on the remote
host accepts input supplied by the client and uses it to launch needed
programs or locate database files. An unauthenticated, remote attacker
can leverage this issue to execute arbitrary commands on the affected
host subject to the privileges under which the service operates, which
under Windows is SYSTEM.

See also :

Solution :

Unknown at this time.

Risk factor :

Critical / CVSS Base Score : 10.0
CVSS Temporal Score : 9.0
Public Exploit Available : true

Family: Gain a shell remotely

Nessus Plugin ID: 31419 ()

Bugtraq ID: 28097

CVE ID: CVE-2008-1319

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now