CVE-2008-1319
Status: ModifiedHigh (9.3)—💥 Exploit
Untrusted search path and argument injection vulnerability in the VersantD service in Versant Object Database 7.0.1.3 and earlier, as used in Borland CaliberRM and probably other products, allows remote attackers to execute arbitrary commands via a request to TCP port 5019 with a modified VERSANT_ROOT field.
CVSS
- Version: 2.0
- Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C
- Base score: 9.3
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 4.80%
- Percentile among all scored CVEs: 92
- Score date: 10/8/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
💥 Public exploits
Exploit code or detection templates are publicly available. This is not the same as confirmed active exploitation (KEV), but it raises the risk: patch with priority.
- Published on Exploit-DB · Versant Object Database 7.0.1.3 - Commands Execution (3/4/2008)
Affected technologies (1)
CWEs
- NVD-CWE-Other
References
- http://aluigi.altervista.org/adv/versantcmd-adv.txt
- http://marc.info/?l=bugtraq&m=120468784112145&w=2
- http://secunia.com/advisories/29230
- http://securityreason.com/securityalert/3738
- http://www.securityfocus.com/archive/1/489139/100/0/threaded
- http://www.securityfocus.com/bid/28097
- http://www.vupen.com/english/advisories/2008/0764/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/40997
- https://www.exploit-db.com/exploits/5213
- http://aluigi.altervista.org/adv/versantcmd-adv.txt
- http://marc.info/?l=bugtraq&m=120468784112145&w=2
- http://secunia.com/advisories/29230
- http://securityreason.com/securityalert/3738
- http://www.securityfocus.com/archive/1/489139/100/0/threaded
- http://www.securityfocus.com/bid/28097
- http://www.vupen.com/english/advisories/2008/0764/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/40997
- https://www.exploit-db.com/exploits/5213
Raw JSON (NVD)
Show
{
"id": "CVE-2008-1319",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 9.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2008-03-13T14:44:00.000",
"references": [
{
"url": "http://aluigi.altervista.org/adv/versantcmd-adv.txt",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://marc.info/?l=bugtraq&m=120468784112145&w=2",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/29230",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://securityreason.com/securityalert/3738",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/489139/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/28097",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2008/0764/references",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/40997",
"source": "cve@mitre.org"
},
{
"url": "https://www.exploit-db.com/exploits/5213",
"source": "cve@mitre.org"
},
{
"url": "http://aluigi.altervista.org/adv/versantcmd-adv.txt",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://marc.info/?l=bugtraq&m=120468784112145&w=2",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/29230",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://securityreason.com/securityalert/3738",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/489139/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/28097",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2008/0764/references",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/40997",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.exploit-db.com/exploits/5213",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Untrusted search path and argument injection vulnerability in the VersantD service in Versant Object Database 7.0.1.3 and earlier, as used in Borland CaliberRM and probably other products, allows remote attackers to execute arbitrary commands via a request to TCP port 5019 with a modified VERSANT_ROOT field."
},
{
"lang": "es",
"value": "Vulnerabilidad de búsqueda no permitida de directorio e inyección de argumentos en el servicio VersantD de Versant Object Database versión 7.0.1.3 y anteriores, usado en Borland CaliberRM y probablemente en otros productos, permite a atacantes remotos ejecutar comandos de su elección mediante una petición al puerto 5019 TCP con el campo VERSANT_ROOT modificado."
}
],
"lastModified": "2026-06-16T22:51:29.440",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:versant:versant_object_database:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AEB981B3-B3F8-420F-A0F6-FA82DB78E240",
"versionEndIncluding": "7.0.1.3"
},
{
"criteria": "cpe:2.3:a:versant:versant_object_database:7.0.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B69E87FF-8CBB-4BB1-9599-977925E0CBD7"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}