Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2009-3369

Опубликовано: 24 сент. 2009
Источник: nvd
CVSS2: 8.5
EPSS Низкий

Описание

CgiUserConfigEdit in BackupPC 3.1.0, when SSH keys and Rsync are in use in a multi-user environment, does not restrict users from the ClientNameAlias function, which allows remote authenticated users to read and write sensitive files by modifying ClientNameAlias to match another system, then initiating a backup or restore.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:backuppc:backuppc:3.1.0:*:*:*:*:*:*:*

EPSS

Процентиль: 86%
0.0294
Низкий

8.5 High

CVSS2

Дефекты

CWE-264

Связанные уязвимости

ubuntu
почти 17 лет назад

CgiUserConfigEdit in BackupPC 3.1.0, when SSH keys and Rsync are in use in a multi-user environment, does not restrict users from the ClientNameAlias function, which allows remote authenticated users to read and write sensitive files by modifying ClientNameAlias to match another system, then initiating a backup or restore.

redhat
почти 17 лет назад

CgiUserConfigEdit in BackupPC 3.1.0, when SSH keys and Rsync are in use in a multi-user environment, does not restrict users from the ClientNameAlias function, which allows remote authenticated users to read and write sensitive files by modifying ClientNameAlias to match another system, then initiating a backup or restore.

debian
почти 17 лет назад

CgiUserConfigEdit in BackupPC 3.1.0, when SSH keys and Rsync are in us ...

github
больше 4 лет назад

CgiUserConfigEdit in BackupPC 3.1.0, when SSH keys and Rsync are in use in a multi-user environment, does not restrict users from the ClientNameAlias function, which allows remote authenticated users to read and write sensitive files by modifying ClientNameAlias to match another system, then initiating a backup or restore.

EPSS

Процентиль: 86%
0.0294
Низкий

8.5 High

CVSS2

Дефекты

CWE-264