Vulnerabilities > CVE-2005-1272
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
Stack-based buffer overflow in the Backup Agent for Microsoft SQL Server in BrightStor ARCserve Backup Agent for SQL Server 11.0 allows remote attackers to execute arbitrary code via a long string sent to port (1) 6070 or (2) 6050.
Vulnerable Configurations
Exploit-Db
description CA BrightStor Agent for Microsoft SQL Overflow. CVE-2005-1272. Remote exploit for windows platform id EDB-ID:16403 last seen 2016-02-01 modified 2010-04-30 published 2010-04-30 reporter metasploit source https://www.exploit-db.com/download/16403/ title CA BrightStor Agent for Microsoft SQL Overflow description CA BrightStor ARCserve Backup Agent (dbasqlr.exe) Remote Exploit. CVE-2005-1272. Remote exploit for windows platform id EDB-ID:1130 last seen 2016-01-31 modified 2005-08-03 published 2005-08-03 reporter cybertronic source https://www.exploit-db.com/download/1130/ title CA BrightStor ARCserve Backup Agent dbasqlr.exe Remote Exploit
Metasploit
description | This module exploits a vulnerability in the CA BrightStor Agent for Microsoft SQL Server. This vulnerability was discovered by cybertronic[at]gmx.net. |
id | MSF:EXPLOIT/WINDOWS/BRIGHTSTOR/SQL_AGENT |
last seen | 2020-06-07 |
modified | 1976-01-01 |
published | 1976-01-01 |
references | |
reporter | Rapid7 |
source | https://github.com/rapid7/metasploit-framework/blob/master//modules/exploits/windows/brightstor/sql_agent.rb |
title | CA BrightStor Agent for Microsoft SQL Overflow |
Nessus
NASL family | Windows |
NASL id | ARCSERVE_MSSQL_AGENT_OVERFLOW.NASL |
description | This host is running BrightStor ARCServe MSSQL Agent. The remote version of this software is susceptible to a buffer overflow attack. An attacker, by sending a specially crafted packet, may be able to execute code on the remote host. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 19387 |
published | 2005-08-05 |
reporter | This script is Copyright (C) 2005-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/19387 |
title | CA BrightStor ARCserve Backup Agent for Windows Long String Overflow |
code |
|
Packetstorm
data source | https://packetstormsecurity.com/files/download/83109/sql_agent.rb.txt |
id | PACKETSTORM:83109 |
last seen | 2016-12-05 |
published | 2009-11-26 |
reporter | H D Moore |
source | https://packetstormsecurity.com/files/83109/CA-BrightStor-Agent-for-Microsoft-SQL-Overflow.html |
title | CA BrightStor Agent for Microsoft SQL Overflow |
Saint
bid | 14453 |
description | BrightStor ARCserve Backup agent for MS-SQL buffer overflow |
id | misc_arcservesql |
osvdb | 18501 |
title | brightstor_arcserve_mssql_agent |
type | remote |