ZeroHour

CVE-2017-15367

PoC
CVSS 3.0
9.8 critical
EPSS
23%p98
Published
()
Modified
Description

Bacula-web before 8.0.0-rc2 is affected by multiple SQL Injection vulnerabilities that could allow an attacker to access the Bacula database and, depending on configuration, escalate privileges on the server.

Vendors
bacula
Products
bacula-web
Weakness
CWE-89
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.