Записи bacula
7 опубликованных записей вендора bacula.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 85,7 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-319 Cleartext Transmission of Sensitive Information1
- CWE-59 Improper Link Resolution Before File Access ('Link Following')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
7 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
46В плане | CVE-2017-15367Proof of concept | Bacula-web before 8.0.0-rc2 is affected by multiple SQL Injection vulnerabilities that could allow an attacker to access the Bacula databasebacula · bacula-web · CWE-89 | Критическая9,8 | — | 23,1 % | 7 мар. 2018 г. |
32Наблюдать | CVE-2025-45346Proof of concept | SQL Injection vulnerability in Bacula-web before v.9.7.1 allows a remote attacker to execute arbitrary code via a crafted HTTP GET request.bacula · bacula-web · CWE-89 | Высокая8,1 | — | 0,7 % | 29 июл. 2025 г. |
31Наблюдать | CVE-2014-8295Proof of concept | SQL injection vulnerability in joblogs.php in Bacula-Web 5.2.10 allows remote attackers to execute arbitrary SQL commands via the jobid parabacula · bacula-web · CWE-89 | Высокая7,5 | — | 2,3 % | 15 окт. 2014 г. |
27Наблюдать | CVE-2008-5373Эксплойта нет | mtx-changer.Adic-Scalar-24 in bacula-common 2.4.2 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/mtx.##### tbacula · bacula · CWE-59 | Средняя6,9 | — | 0,4 % | 8 дек. 2008 г. |
22Наблюдать | CVE-2007-5626Эксплойта нет | make_catalog_backup in Bacula 2.2.5, and probably earlier, sends a MySQL password as a command line argument, and sometimes transmits cleartbacula · bacula · CWE-319 | Средняя5,5 | — | 0,3 % | 23 окт. 2007 г. |
17Наблюдать | CVE-2012-4430Эксплойта нет | The dump_resource function in dird/dird_conf.c in Bacula before 5.2.11 does not properly enforce ACL rules, which allows remote authenticatebacula · bacula · CWE-264 | Средняя4,0 | — | 2,7 % | 10 окт. 2012 г. |
14Наблюдать | CVE-2005-2995Эксплойта нет | bacula 1.36.3 and earlier allows local users to modify or read sensitive files via symlink attacks on (1) the temporary file used by autoconbacula · bacula | Низкая3,6 | — | 0,4 % | 20 сент. 2005 г. |
- CVE-2017-1536746В плане
Bacula-web before 8.0.0-rc2 is affected by multiple SQL Injection vulnerabilities that could allow an attacker to access the Bacula database
КритическаяCVSS 9,8Proof of conceptEPSS 23 %bacula · bacula-web7 мар. 2018 г.
- CVE-2025-4534632Наблюдать
SQL Injection vulnerability in Bacula-web before v.9.7.1 allows a remote attacker to execute arbitrary code via a crafted HTTP GET request.
ВысокаяCVSS 8,1Proof of conceptEPSS 1 %bacula · bacula-web29 июл. 2025 г.
- CVE-2014-829531Наблюдать
SQL injection vulnerability in joblogs.php in Bacula-Web 5.2.10 allows remote attackers to execute arbitrary SQL commands via the jobid para
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %bacula · bacula-web15 окт. 2014 г.
- CVE-2008-537327Наблюдать
mtx-changer.Adic-Scalar-24 in bacula-common 2.4.2 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/mtx.##### t
СредняяCVSS 6,9Эксплойта нетEPSS 0 %bacula · bacula8 дек. 2008 г.
- CVE-2007-562622Наблюдать
make_catalog_backup in Bacula 2.2.5, and probably earlier, sends a MySQL password as a command line argument, and sometimes transmits cleart
СредняяCVSS 5,5Эксплойта нетEPSS 0 %bacula · bacula23 окт. 2007 г.
- CVE-2012-443017Наблюдать
The dump_resource function in dird/dird_conf.c in Bacula before 5.2.11 does not properly enforce ACL rules, which allows remote authenticate
СредняяCVSS 4,0Эксплойта нетEPSS 3 %bacula · bacula10 окт. 2012 г.
- CVE-2005-299514Наблюдать
bacula 1.36.3 and earlier allows local users to modify or read sensitive files via symlink attacks on (1) the temporary file used by autocon
НизкаяCVSS 3,6Эксплойта нетEPSS 0 %bacula · bacula20 сент. 2005 г.