CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
104099 | CVE-2017-7279 | Candidate | An unprivileged user of the Unitrends Enterprise Backup before 9.0.0 web server can escalate to root privileges by modifying the "token" cookie issued at login. | Assigned (20170327) | None (candidate not yet proposed) | View | |
104100 | CVE-2017-7280 | Candidate | An issue was discovered in api/includes/systems.php in Unitrends Enterprise Backup before 9.0.0. User input is not properly filtered before being sent to a popen function. This allows for remote code execution by sending a specially crafted user variable. | Assigned (20170327) | None (candidate not yet proposed) | View | |
104101 | CVE-2017-7281 | Candidate | An issue was discovered in Unitrends Enterprise Backup before 9.1.2. A lack of sanitization of user input in the createReportName and saveReport functions in recoveryconsole/bpl/reports.php allows for an authenticated user to create a randomly named file on disk with a user-controlled extension, contents, and path, leading to remote code execution, aka Unrestricted File Upload. | Assigned (20170327) | None (candidate not yet proposed) | View | |
104102 | CVE-2017-7282 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20170327) | None (candidate not yet proposed) | View | |
104103 | CVE-2017-7283 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20170327) | None (candidate not yet proposed) | View |
Page 20221 of 20943, showing 5 records out of 104715 total, starting on record 101101, ending on 101105