10
CVSSv2

CVE-2014-3008

Published: 28/04/2014 Updated: 29/08/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Unitrends Enterprise Backup 7.3.0 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the comm parameter to recoveryconsole/bpl/snmpd.php.

Vulnerable Product Search on Vulmon Subscribe to Product

unitrends enterprise backup 7.3.0

Exploits

Unitrends Enterprise Backup 730 Multiple vulnerabilities exist within this piece of software The largest one is likely the fact that the ‘auth’ string used for authorization isn’t random at all After authentication, any requests made by the browser send no cookies and only check this ‘auth’ param, which is completely insufficient Be ...