CVE-2007-5005

CA BrightStor ARCserve Backup r11.0-r11.5 - Unauthenticated Path Traversal & Arbitrary File Write

Title source: llm
STIX 2.1

Description

Directory traversal vulnerability in rxRPC.dll in CA (Computer Associates) BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.5 allows remote attackers to upload and overwrite arbitrary files via a ..\ (dot dot backslash) sequence in the destination filename argument to sub-function 8 in the rxrReceiveFileFromServer command.

References (8)

Core 8
Core References
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/25606
Various Sources third-party-advisory x_refsource_eeye
http://research.eeye.com/html/advisories/published/AD20070920.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/24348
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/480252/100/100/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1018728

Scores

EPSS 0.0380
EPSS Percentile 88.2%

Details

CWE
CWE-22
Status published
Products (8)
broadcom/brightstor_arcserve_backup_laptops_desktops 4.0
broadcom/brightstor_arcserve_backup_laptops_desktops 11.0
broadcom/brightstor_arcserve_backup_laptops_desktops 11.1 (2 CPE variants)
broadcom/brightstor_arcserve_backup_laptops_desktops 11.5
broadcom/desktop_management_suite 11.0
broadcom/desktop_management_suite 11.1
broadcom/desktop_management_suite 11.2
ca/protection_suites r2
Published Oct 01, 2007
Tracked Since Feb 18, 2026