It was discovered that the Unitrends Backup (UB) before 10.1.0 user interface was exposed to an authentication bypass, which then could allow an unauthenticated user to inject arbitrary commands into its /api/hosts parameters using backquotes.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T06:01:48.697Z
Reserved: 2018-01-26T00:00:00
Link: CVE-2018-6328
No data.
Status : Modified
Published: 2018-03-14T19:29:00.597
Modified: 2024-11-21T04:10:29.507
Link: CVE-2018-6328
No data.
OpenCVE Enrichment
No data.
Weaknesses