Directory traversal vulnerability in the RPC interface (asdbapi.dll) in CA ARCserve Backup (formerly BrightStor ARCserve Backup) r11.1 through r12.0 allows remote attackers to execute arbitrary commands via a .. (dot dot) in an RPC call with opnum 0x10A.
https://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=188143
https://exchange.xforce.ibmcloud.com/vulnerabilities/45774
http://www.vupen.com/english/advisories/2008/2777
http://www.securitytracker.com/id?1021032
http://www.securityfocus.com/bid/31684
http://www.securityfocus.com/archive/1/497281/100/0/threaded
http://www.securityfocus.com/archive/1/497218