unitrends kayıtları
unitrends üreticisine ait 10 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 1 · %10
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-287 Improper Authentication2
- CWE-20 Improper Input Validation2
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
10 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
57Planlayın | CVE-2018-6329Silahlaştırılmış | It was discovered that the Unitrends Backup (UB) before 10.1.0 libbpext.so authentication could be bypassed with a SQL injection, allowing aunitrends · backup · CWE-89 | Kritik9,8 | — | %61,2 | 14 Mar 2018 |
42Planlayın | CVE-2014-3008Kavram kanıtı | Unitrends Enterprise Backup 7.3.0 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the comm paramunitrends · enterprise backup · CWE-78 | Kritik10,0 | — | %7,0 | 28 Nis 2014 |
41Planlayın | CVE-2017-7280İstismar yok | An issue was discovered in api/includes/systems.php in Unitrends Enterprise Backup before 9.0.0.unitrends · enterprise backup · CWE-20 | Kritik9,8 | — | %6,2 | 12 Nis 2017 |
40Planlayın | CVE-2017-7279İstismar yok | An unprivileged user of the Unitrends Enterprise Backup before 9.0.0 web server can escalate to root privileges by modifying the "token" coounitrends · enterprise backup · CWE-565 | Kritik9,8 | — | %4,4 | 12 Nis 2017 |
39İzleyin | CVE-2020-8427İstismar yok | In Unitrends Backup before 10.4.1, an HTTP request parameter was not properly sanitized, allowing for SQL injection that resulted in an authunitrends · backup · CWE-89 | Kritik9,8 | — | %1,5 | 17 Şub 2020 |
36İzleyin | CVE-2017-7281İstismar yok | An issue was discovered in Unitrends Enterprise Backup before 9.1.2.unitrends · enterprise backup · CWE-434 | Yüksek8,8 | — | %4,3 | 12 Nis 2017 |
36İzleyin | CVE-2017-7283İstismar yok | An authenticated user of Unitrends Enterprise Backup before 9.1.2 can execute arbitrary OS commands by sending a specially crafted filename unitrends · enterprise backup · CWE-20 | Yüksek8,8 | — | %4,3 | 19 Nis 2017 |
36İzleyin | CVE-2017-7284İstismar yok | An attacker that has hijacked a Unitrends Enterprise Backup (before 9.1.2) web server session can leverage api/includes/users.php to change unitrends · enterprise backup · CWE-287 | Yüksek8,8 | — | %2,7 | 12 Nis 2017 |
31İzleyin | CVE-2014-3139Kavram kanıtı | recoveryconsole/bpl/snmpd.php in Unitrends Enterprise Backup 7.3.0 allows remote attackers to bypass authentication by setting the auth paraunitrends · enterprise backup · CWE-287 | Yüksek7,5 | — | %3,3 | 2 May 2014 |
23İzleyin | CVE-2017-7282İstismar yok | An issue was discovered in Unitrends Enterprise Backup before 9.1.1.unitrends · enterprise backup · CWE-200 | Orta5,5 | — | %4,3 | 19 Nis 2017 |
- CVE-2018-632957Planlayın
It was discovered that the Unitrends Backup (UB) before 10.1.0 libbpext.so authentication could be bypassed with a SQL injection, allowing a
KritikCVSS 9,8SilahlaştırılmışEPSS %61unitrends · backup14 Mar 2018
- CVE-2014-300842Planlayın
Unitrends Enterprise Backup 7.3.0 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the comm param
KritikCVSS 10,0Kavram kanıtıEPSS %7unitrends · enterprise backup28 Nis 2014
- CVE-2017-728041Planlayın
An issue was discovered in api/includes/systems.php in Unitrends Enterprise Backup before 9.0.0.
KritikCVSS 9,8İstismar yokEPSS %6unitrends · enterprise backup12 Nis 2017
- CVE-2017-727940Planlayın
An unprivileged user of the Unitrends Enterprise Backup before 9.0.0 web server can escalate to root privileges by modifying the "token" coo
KritikCVSS 9,8İstismar yokEPSS %4unitrends · enterprise backup12 Nis 2017
- CVE-2020-842739İzleyin
In Unitrends Backup before 10.4.1, an HTTP request parameter was not properly sanitized, allowing for SQL injection that resulted in an auth
KritikCVSS 9,8İstismar yokEPSS %2unitrends · backup17 Şub 2020
- CVE-2017-728136İzleyin
An issue was discovered in Unitrends Enterprise Backup before 9.1.2.
YüksekCVSS 8,8İstismar yokEPSS %4unitrends · enterprise backup12 Nis 2017
- CVE-2017-728336İzleyin
An authenticated user of Unitrends Enterprise Backup before 9.1.2 can execute arbitrary OS commands by sending a specially crafted filename
YüksekCVSS 8,8İstismar yokEPSS %4unitrends · enterprise backup19 Nis 2017
- CVE-2017-728436İzleyin
An attacker that has hijacked a Unitrends Enterprise Backup (before 9.1.2) web server session can leverage api/includes/users.php to change
YüksekCVSS 8,8İstismar yokEPSS %3unitrends · enterprise backup12 Nis 2017
- CVE-2014-313931İzleyin
recoveryconsole/bpl/snmpd.php in Unitrends Enterprise Backup 7.3.0 allows remote attackers to bypass authentication by setting the auth para
YüksekCVSS 7,5Kavram kanıtıEPSS %3unitrends · enterprise backup2 May 2014
- CVE-2017-728223İzleyin
An issue was discovered in Unitrends Enterprise Backup before 9.1.1.
OrtaCVSS 5,5İstismar yokEPSS %4unitrends · enterprise backup19 Nis 2017