CVE List

Id CVE No. Status Description Phase Votes Comments Actions
104099  CVE-2017-7279  Candidate  An unprivileged user of the Unitrends Enterprise Backup before 9.0.0 web server can escalate to root privileges by modifying the "token" cookie issued at login.  Assigned (20170327)  None (candidate not yet proposed)    View
104100  CVE-2017-7280  Candidate  An issue was discovered in api/includes/systems.php in Unitrends Enterprise Backup before 9.0.0. User input is not properly filtered before being sent to a popen function. This allows for remote code execution by sending a specially crafted user variable.  Assigned (20170327)  None (candidate not yet proposed)    View
104101  CVE-2017-7281  Candidate  An issue was discovered in Unitrends Enterprise Backup before 9.1.2. A lack of sanitization of user input in the createReportName and saveReport functions in recoveryconsole/bpl/reports.php allows for an authenticated user to create a randomly named file on disk with a user-controlled extension, contents, and path, leading to remote code execution, aka Unrestricted File Upload.  Assigned (20170327)  None (candidate not yet proposed)    View
104102  CVE-2017-7282  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170327)  None (candidate not yet proposed)    View
104103  CVE-2017-7283  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170327)  None (candidate not yet proposed)    View

Page 20221 of 20943, showing 5 records out of 104715 total, starting on record 101101, ending on 101105

Actions