ZeroHour

CVE-2018-6328

PoC ×2
CVSS 3.0
9.8 critical
EPSS
64%p99
Published
()
Modified
Description

It was discovered that the Unitrends Backup (UB) before 10.1.0 user interface was exposed to an authentication bypass, which then could allow an unauthenticated user to inject arbitrary commands into its /api/hosts parameters using backquotes.

Vendors
kaseya
Products
unitrends backup
Weakness
CWE-287
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.