CVE-2008-2286

Symantec Altiris Deployment Solution - SQL Injection

Title source: rule

Description

SQL injection vulnerability in axengine.exe in Symantec Altiris Deployment Solution 6.8.x and 6.9.x before 6.9.176 allows remote attackers to execute arbitrary SQL commands via unspecified string fields in a notification packet.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/29552
metasploit WORKING POC NORMAL
by Brett Moore, 3v0lver · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/misc/altiris_ds_sqli.rb

Scores

EPSS 0.3975
EPSS Percentile 97.3%

Details

CWE
CWE-89
Status published
Products (2)
symantec/altiris_deployment_solution 6.8
symantec/altiris_deployment_solution 6.9
Published May 18, 2008
Tracked Since Feb 18, 2026