Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2009-3369

Опубликовано: 24 сент. 2009
Источник: nvd
CVSS2: 8.5
EPSS Низкий

Описание

CgiUserConfigEdit in BackupPC 3.1.0, when SSH keys and Rsync are in use in a multi-user environment, does not restrict users from the ClientNameAlias function, which allows remote authenticated users to read and write sensitive files by modifying ClientNameAlias to match another system, then initiating a backup or restore.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:backuppc:backuppc:3.1.0:*:*:*:*:*:*:*

EPSS

Процентиль: 89%
0.0443
Низкий

8.5 High

CVSS2

Дефекты

CWE-264

Связанные уязвимости

ubuntu
около 16 лет назад

CgiUserConfigEdit in BackupPC 3.1.0, when SSH keys and Rsync are in use in a multi-user environment, does not restrict users from the ClientNameAlias function, which allows remote authenticated users to read and write sensitive files by modifying ClientNameAlias to match another system, then initiating a backup or restore.

redhat
больше 16 лет назад

CgiUserConfigEdit in BackupPC 3.1.0, when SSH keys and Rsync are in use in a multi-user environment, does not restrict users from the ClientNameAlias function, which allows remote authenticated users to read and write sensitive files by modifying ClientNameAlias to match another system, then initiating a backup or restore.

debian
около 16 лет назад

CgiUserConfigEdit in BackupPC 3.1.0, when SSH keys and Rsync are in us ...

github
больше 3 лет назад

CgiUserConfigEdit in BackupPC 3.1.0, when SSH keys and Rsync are in use in a multi-user environment, does not restrict users from the ClientNameAlias function, which allows remote authenticated users to read and write sensitive files by modifying ClientNameAlias to match another system, then initiating a backup or restore.

EPSS

Процентиль: 89%
0.0443
Низкий

8.5 High

CVSS2

Дефекты

CWE-264