First published: Sun May 18 2008(Updated: )
SQL injection vulnerability in axengine.exe in Symantec Altiris Deployment Solution 6.8.x and 6.9.x before 6.9.176 allows remote attackers to execute arbitrary SQL commands via unspecified string fields in a notification packet.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Symantec Altiris Deployment Solution | =6.9 | |
Symantec Altiris Deployment Solution | =6.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-2286 is considered a high severity vulnerability due to its potential for remote exploitation and arbitrary SQL command execution.
To remediate CVE-2008-2286, it is recommended to update Symantec Altiris Deployment Solution to version 6.9.176 or later.
CVE-2008-2286 allows remote attackers to execute arbitrary SQL commands, leading to potential data compromise and system control.
CVE-2008-2286 affects Symantec Altiris Deployment Solution versions 6.8.x and 6.9.x prior to 6.9.176.
Yes, CVE-2008-2286 is exploitable remotely, allowing attackers to execute arbitrary SQL commands without physical access.