Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-6328

Опубликовано: 14 мар. 2018
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Высокий

Описание

It was discovered that the Unitrends Backup (UB) before 10.1.0 user interface was exposed to an authentication bypass, which then could allow an unauthenticated user to inject arbitrary commands into its /api/hosts parameters using backquotes.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:kaseya:unitrends_backup:*:*:*:*:*:*:*:*
Версия до 10.1 (исключая)

EPSS

Процентиль: 99%
0.70958
Высокий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 9.8
github
больше 3 лет назад

It was discovered that the Unitrends Backup (UB) before 10.1.0 user interface was exposed to an authentication bypass, which then could allow an unauthenticated user to inject arbitrary commands into its /api/hosts parameters using backquotes.

EPSS

Процентиль: 99%
0.70958
Высокий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-287