7.1
CVSSv2

CVE-2017-7282

Published: 20/04/2017 Updated: 25/04/2017
CVSS v2 Base Score: 7.1 | Impact Score: 6.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 634
Vector: AV:N/AC:M/Au:N/C:C/I:N/A:N

Vulnerability Summary

An issue exists in Unitrends Enterprise Backup prior to 9.1.1. The function downloadFile in api/includes/restore.php blindly accepts any filename passed to /api/restore/download as valid. This allows an authenticated malicious user to read any file in the filesystem that the web server has access to, aka Local File Inclusion (LFI).

Vulnerable Product Search on Vulmon Subscribe to Product

unitrends enterprise backup

Github Repositories

Rhino CVE Proof-of-Concept Exploits A collection of proof-of-concept exploit scripts written by the team at Rhino Security Labs for various CVEs CVE-2020-5377 & CVE-2021-21514: Dell OpenManage Server Administrator Arbitrary File Read CVE-2020-13405: MicroWeber Unauthenticated User Database Disclosure CVE-2019-16116: CompleteFTP Server Local Privilege Escalation CVE‑

A collection of proof-of-concept exploit scripts written by the team at Rhino Security Labs for various CVEs.

Rhino CVE Proof-of-Concept Exploits A collection of proof-of-concept exploit scripts written by the team at Rhino Security Labs for various CVEs CVE-2022-25372: Local Privilege Escalation In Pritunl VPN Client CVE-2022-25237: Authorization Bypass Leading to RCE in Bonitasoft Web CVE-2022-25166: AWS VPN Client Arbitrary File Write as SYSTEM CVE-2022-25165: AWS VPN Client Infor

Rhino CVE Proof-of-Concept Exploits A collection of proof-of-concept exploit scripts written by the team at Rhino Security Labs for various CVEs CVE-2022-25372: Local Privilege Escalation In Pritunl VPN Client CVE-2022-25237: Authorization Bypass Leading to RCE in Bonitasoft Web CVE-2022-25166: AWS VPN Client Arbitrary File Write as SYSTEM CVE-2022-25165: AWS VPN Client Infor

Rhino CVE Proof-of-Concept Exploits A collection of proof-of-concept exploit scripts written by the team at Rhino Security Labs for various CVEs CVE-2022-25372: Local Privilege Escalation In Pritunl VPN Client CVE-2022-25237: Authorization Bypass Leading to RCE in Bonitasoft Web CVE-2022-25166: AWS VPN Client Arbitrary File Write as SYSTEM CVE-2022-25165: AWS VPN Client Infor

A collection of proof-of-concept exploit scripts written by the team at Rhino Security Labs for various CVEs.

Rhino CVE Proof-of-Concept Exploits A collection of proof-of-concept exploit scripts written by the team at Rhino Security Labs for various CVEs CVE-2022-25372: Local Privilege Escalation In Pritunl VPN Client CVE-2022-25237: Authorization Bypass Leading to RCE in Bonitasoft Web CVE-2022-25166: AWS VPN Client Arbitrary File Write as SYSTEM CVE-2022-25165: AWS VPN Client Infor

Awesome CVE PoC ✍️ A curated list of CVE PoCs Here is a collection about Proof of Concepts of C

Awesome CVE PoC ✍️ A curated list of CVE PoCs Here is a collection about Proof of Concepts of C

✍️ A curated list of CVE PoCs.

Awesome CVE PoC ✍️ A curated list of CVE PoCs Here is a collection about Proof of Concepts of C