CVE-2008-2286: SQL Injection
SQL injection vulnerability in axengine.exe in Symantec Altiris Deployment Solution 6.8.x and 6.9.x before 6.9.176 allows remote attackers to execute arbitrary SQL commands via unspecified string fields in a notification packet.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2008-2286?
CVE-2008-2286 is considered a high severity vulnerability due to its potential for remote exploitation and arbitrary SQL command execution.
How do I fix CVE-2008-2286?
To remediate CVE-2008-2286, it is recommended to update Symantec Altiris Deployment Solution to version 6.9.176 or later.
What is the impact of CVE-2008-2286?
CVE-2008-2286 allows remote attackers to execute arbitrary SQL commands, leading to potential data compromise and system control.
Which software versions are affected by CVE-2008-2286?
CVE-2008-2286 affects Symantec Altiris Deployment Solution versions 6.8.x and 6.9.x prior to 6.9.176.
Is CVE-2008-2286 exploitable remotely?
Yes, CVE-2008-2286 is exploitable remotely, allowing attackers to execute arbitrary SQL commands without physical access.