CVE-2017-15367

Bacula-web before 8.0.0-rc2 is affected by multiple SQL Injection vulnerabilities that could allow an attacker to access the Bacula database and, depending on configuration, escalate privileges on the server.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:bacula:bacula-web:8.0.0:rc1:*:*:*:*:*:*
cpe:2.3:a:bacula:bacula-web:*:*:*:*:*:*:*:*

Information

Published : 2018-03-07 12:29

Updated : 2018-10-09 08:07


NVD link : CVE-2017-15367

Mitre link : CVE-2017-15367


JSON object : View

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Advertisement

dedicated server usa

Products Affected

bacula

  • bacula-web