Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
unitrends enterprise backup vulnerabilities and exploits
(subscribe to this query)
9
CVSSv2
CVE-2017-7283
An authenticated user of Unitrends Enterprise Backup prior to 9.1.2 can execute arbitrary OS commands by sending a specially crafted filename to the /api/restore/download-files endpoint, related to the downloadFiles function in api/includes/restore.php.
Unitrends Enterprise Backup
10
CVSSv2
CVE-2017-7279
An unprivileged user of the Unitrends Enterprise Backup prior to 9.0.0 web server can escalate to root privileges by modifying the "token" cookie issued at login.
Unitrends Enterprise Backup
7.5
CVSSv2
CVE-2017-7280
An issue exists in api/includes/systems.php in Unitrends Enterprise Backup prior to 9.0.0. User input is not properly filtered before being sent to a popen function. This allows for remote code execution by sending a specially crafted user variable.
Unitrends Enterprise Backup
6.5
CVSSv2
CVE-2017-7281
An issue exists in Unitrends Enterprise Backup prior to 9.1.2. A lack of sanitization of user input in the createReportName and saveReport functions in recoveryconsole/bpl/reports.php allows for an authenticated user to create a randomly named file on disk with a user-controlled ...
Unitrends Enterprise Backup
7.1
CVSSv2
CVE-2017-7282
An issue exists in Unitrends Enterprise Backup prior to 9.1.1. The function downloadFile in api/includes/restore.php blindly accepts any filename passed to /api/restore/download as valid. This allows an authenticated malicious user to read any file in the filesystem that the web ...
Unitrends Enterprise Backup
6.5
CVSSv2
CVE-2017-7284
An attacker that has hijacked a Unitrends Enterprise Backup (prior to 9.1.2) web server session can leverage api/includes/users.php to change the password of the logged in account without knowing the current password. This allows for an account takeover.
Unitrends Enterprise Backup
10
CVSSv2
CVE-2014-3008
Unitrends Enterprise Backup 7.3.0 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the comm parameter to recoveryconsole/bpl/snmpd.php.
Unitrends Enterprise Backup 7.3.0
1 EDB exploit
7.5
CVSSv2
CVE-2014-3139
recoveryconsole/bpl/snmpd.php in Unitrends Enterprise Backup 7.3.0 allows remote malicious users to bypass authentication by setting the auth parameter to a certain string.
Unitrends Enterprise Backup 7.3.0
1 EDB exploit
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-33228
CVE-2024-20361
log injection
bypass
CVE-2024-4985
CVE-2024-35223
CVE-2024-29849
CVE-2024-31893
IMAP
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started