An issue was discovered in Unitrends Enterprise Backup before 9.1.1. The function downloadFile in api/includes/restore.php blindly accepts any filename passed to /api/restore/download as valid. This allows an authenticated attacker to read any file in the filesystem that the web server has access to, aka Local File Inclusion (LFI).
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2017-04-20T02:43:00

Updated: 2024-08-05T15:56:36.337Z

Reserved: 2017-03-27T00:00:00

Link: CVE-2017-7282

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2017-04-20T02:59:00.190

Modified: 2017-04-25T00:36:45.703

Link: CVE-2017-7282

cve-icon Redhat

No data.