NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
84783 | CVE-2017-7279 | An unprivileged user of the Unitrends Enterprise Backup before 9.0.0 web server can escalate to root privileges by modifying the token cookie issued at login. | 2 | 10 | High | 2017-04-27 | 2017-04-20 | View | |
84784 | CVE-2017-7280 | An issue was discovered in api/includes/systems.php in Unitrends Enterprise Backup before 9.0.0. User input is not properly filtered before being sent to a popen function. This allows for remote code execution by sending a specially crafted user variable. | 2 | 7.5 | High | 2017-04-27 | 2017-04-20 | View | |
84785 | CVE-2017-7281 | An issue was discovered in Unitrends Enterprise Backup before 9.1.2. A lack of sanitization of user input in the createReportName and saveReport functions in recoveryconsole/bpl/reports.php allows for an authenticated user to create a randomly named file on disk with a user-controlled extension, contents, and path, leading to remote code execution, aka Unrestricted File Upload. | 2 | 6.5 | Medium | 2017-04-27 | 2017-04-20 | View | |
46897 | CVE-2012-5881 | Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.4.0 through 2.9.0 allows remote attackers to inject arbitrary web script or HTML via vectors related to charts.swf, a similar issue to CVE-2010-4207. | 2 | 4.3 | Medium | 2017-04-27 | 2017-04-20 | View | |
46898 | CVE-2012-5882 | Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.5.0 through 2.9.0 allows remote attackers to inject arbitrary web script or HTML via vectors related to uploader.swf, a similar issue to CVE-2010-4208. | 2 | 4.3 | Medium | 2017-04-27 | 2017-04-20 | View |
Page 1800 of 17672, showing 5 records out of 88360 total, starting on record 8996, ending on 9000