CVE-2008-0457
Unrestricted file upload vulnerability in the FileUpload class running on the Symantec LiveState Apache Tomcat server, as used by Symantec Backup Exec System Recovery Manager 7.0 and 7.0.1, allows remote attackers to upload and execute arbitrary JSP files via unknown vectors.
- Affected products
- Apache Tomcat, Symantec Backup Exec System Recovery Manager
- Symantec Backupexec System Recovery
- = 7.0, 7.01
- Fix
- Available
- CVSS 2.0
- 10.0 HIGH
- EPSS
- 11.9% (96th percentile)
- Weakness
- CWE-20
- NVD status
- Modified
- Published
- 2008-02-07
CVE-2008-0457 at NVD
4 known exploits for CVE-2008-0457
Proof-of-concept code and exploit modules indexed by Sploitus