Логотип exploitDog
bind:CVE-2017-12479
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2017-12479

Количество 2

Количество 2

nvd логотип

CVE-2017-12479

больше 8 лет назад

It was discovered that an issue in the session logic in Unitrends Backup (UB) before 10.0.0 allowed using the LOGDIR environment variable during a web session to elevate an existing low-privilege user to root privileges. A remote attacker with existing low-privilege credentials could then execute arbitrary commands with root privileges.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-qm9m-fp5f-xg9x

больше 3 лет назад

It was discovered that an issue in the session logic in Unitrends Backup (UB) before 10.0.0 allowed using the LOGDIR environment variable during a web session to elevate an existing low-privilege user to root privileges. A remote attacker with existing low-privilege credentials could then execute arbitrary commands with root privileges.

CVSS3: 8.8
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2017-12479

It was discovered that an issue in the session logic in Unitrends Backup (UB) before 10.0.0 allowed using the LOGDIR environment variable during a web session to elevate an existing low-privilege user to root privileges. A remote attacker with existing low-privilege credentials could then execute arbitrary commands with root privileges.

CVSS3: 8.8
13%
Средний
больше 8 лет назад
github логотип
GHSA-qm9m-fp5f-xg9x

It was discovered that an issue in the session logic in Unitrends Backup (UB) before 10.0.0 allowed using the LOGDIR environment variable during a web session to elevate an existing low-privilege user to root privileges. A remote attacker with existing low-privilege credentials could then execute arbitrary commands with root privileges.

CVSS3: 8.8
13%
Средний
больше 3 лет назад

Уязвимостей на страницу