urbackup records
4 published records for vendor urbackup.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-20 Improper Input Validation1
- CWE-203 Observable Discrepancy1
- CWE-476 NULL Pointer Dereference1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
30Monitor | CVE-2018-20013No exploit | In UrBackup 2.2.6, an attacker can send a malformed request to the client over the network, and trigger a fileservplugin/CClientThread.cpp Curbackup · urbackup · CWE-20 | High7.5 | — | 1.4% | Jun 18, 2019 |
30Monitor | CVE-2018-20014No exploit | In UrBackup 2.2.6, an attacker can send a malformed request to the client over the network, and trigger a fileservplugin/CClientThread.cpp Curbackup · urbackup · CWE-476 | High7.5 | — | 1.4% | Jun 7, 2019 |
24Monitor | CVE-2017-16950No exploit | Cross - site scripting (XSS) vulnerability in UrBackup Server before 2.1.20 allows remote attackers to inject arbitrary web script or HTML vurbackup · urbackup server · CWE-79 | Medium6.1 | — | 0.8% | Dec 17, 2017 |
21Monitor | CVE-2023-47102Proof of concept | UrBackup Server 2.5.31 allows brute-force enumeration of user accounts because a failure message confirms that a username is not valid.urbackup · urbackup server · CWE-203 | Medium5.3 | — | 0.6% | Nov 7, 2023 |
- CVE-2018-2001330Monitor
In UrBackup 2.2.6, an attacker can send a malformed request to the client over the network, and trigger a fileservplugin/CClientThread.cpp C
HighCVSS 7.5No exploitEPSS 1%urbackup · urbackupJun 18, 2019
- CVE-2018-2001430Monitor
In UrBackup 2.2.6, an attacker can send a malformed request to the client over the network, and trigger a fileservplugin/CClientThread.cpp C
HighCVSS 7.5No exploitEPSS 1%urbackup · urbackupJun 7, 2019
- CVE-2017-1695024Monitor
Cross - site scripting (XSS) vulnerability in UrBackup Server before 2.1.20 allows remote attackers to inject arbitrary web script or HTML v
MediumCVSS 6.1No exploitEPSS 1%urbackup · urbackup serverDec 17, 2017
- CVE-2023-4710221Monitor
UrBackup Server 2.5.31 allows brute-force enumeration of user accounts because a failure message confirms that a username is not valid.
MediumCVSS 5.3Proof of conceptEPSS 1%urbackup · urbackup serverNov 7, 2023