ZeroHour

CVE-2021-39392

CVSS 3.1
9.8 critical
EPSS
2%p82
Published
()
Modified
Description

The management tool in MyLittleBackup up to and including 1.7 allows remote attackers to execute arbitrary code because machineKey is hardcoded (the same for all customers' installations) in web.config, and can be used to send serialized ASP code.

Vendors
mylittletools
Products
mylittlebackup
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.