Unitrends Enterprise Backup Multiple Security Vulnerabilities
BID:66928
Info
Unitrends Enterprise Backup Multiple Security Vulnerabilities
| Bugtraq ID: | 66928 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-3008 CVE-2014-3139 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 15 2014 12:00AM |
| Updated: | May 09 2014 12:50AM |
| Credit: | Brandon Perry |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Unitrends Enterprise Backup Multiple Security Vulnerabilities
Unitrends Enterprise Backup is prone to a command-injection and a security-bypass vulnerability.
Successfully exploiting these issues may allow an attacker to execute arbitrary OS commands in the context of the affected application.
Unitrends Enterprise Backup 7.3.0 is vulnerable; other versions may also be affected.
Unitrends Enterprise Backup is prone to a command-injection and a security-bypass vulnerability.
Successfully exploiting these issues may allow an attacker to execute arbitrary OS commands in the context of the affected application.
Unitrends Enterprise Backup 7.3.0 is vulnerable; other versions may also be affected.
Exploit / POC
Unitrends Enterprise Backup Multiple Security Vulnerabilities
Attackers can use readily available tools to exploit these issues. The following metasploit module is available:
Attackers can use readily available tools to exploit these issues. The following metasploit module is available:
Solution / Fix
Unitrends Enterprise Backup Multiple Security Vulnerabilities
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
Unitrends Enterprise Backup Multiple Security Vulnerabilities
References:
References: