Перейти к содержимому
Noroxi

Записи unitrends

10 опубликованных записей вендора unitrends.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
1 · 10 %
Pre-auth RCE
3
С записью об исправлении
0 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

10 записей
  • CVE-2018-6329
    57В плане

    It was discovered that the Unitrends Backup (UB) before 10.1.0 libbpext.so authentication could be bypassed with a SQL injection, allowing a

    КритическаяCVSS 9,8Готовый эксплойтEPSS 61 %

    unitrends · backup14 мар. 2018 г.

  • CVE-2014-3008
    42В плане

    Unitrends Enterprise Backup 7.3.0 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the comm param

    КритическаяCVSS 10,0Proof of conceptEPSS 7 %

    unitrends · enterprise backup28 апр. 2014 г.

  • CVE-2017-7280
    41В плане

    An issue was discovered in api/includes/systems.php in Unitrends Enterprise Backup before 9.0.0.

    КритическаяCVSS 9,8Эксплойта нетEPSS 6 %

    unitrends · enterprise backup12 апр. 2017 г.

  • CVE-2017-7279
    40В плане

    An unprivileged user of the Unitrends Enterprise Backup before 9.0.0 web server can escalate to root privileges by modifying the "token" coo

    КритическаяCVSS 9,8Эксплойта нетEPSS 4 %

    unitrends · enterprise backup12 апр. 2017 г.

  • CVE-2020-8427
    39Наблюдать

    In Unitrends Backup before 10.4.1, an HTTP request parameter was not properly sanitized, allowing for SQL injection that resulted in an auth

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    unitrends · backup17 февр. 2020 г.

  • CVE-2017-7281
    36Наблюдать

    An issue was discovered in Unitrends Enterprise Backup before 9.1.2.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 4 %

    unitrends · enterprise backup12 апр. 2017 г.

  • CVE-2017-7283
    36Наблюдать

    An authenticated user of Unitrends Enterprise Backup before 9.1.2 can execute arbitrary OS commands by sending a specially crafted filename

    ВысокаяCVSS 8,8Эксплойта нетEPSS 4 %

    unitrends · enterprise backup19 апр. 2017 г.

  • CVE-2017-7284
    36Наблюдать

    An attacker that has hijacked a Unitrends Enterprise Backup (before 9.1.2) web server session can leverage api/includes/users.php to change

    ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %

    unitrends · enterprise backup12 апр. 2017 г.

  • CVE-2014-3139
    31Наблюдать

    recoveryconsole/bpl/snmpd.php in Unitrends Enterprise Backup 7.3.0 allows remote attackers to bypass authentication by setting the auth para

    ВысокаяCVSS 7,5Proof of conceptEPSS 3 %

    unitrends · enterprise backup2 мая 2014 г.

  • CVE-2017-7282
    23Наблюдать

    An issue was discovered in Unitrends Enterprise Backup before 9.1.1.

    СредняяCVSS 5,5Эксплойта нетEPSS 4 %

    unitrends · enterprise backup19 апр. 2017 г.