CVE-2017-7283

An authenticated user of Unitrends Enterprise Backup before 9.1.2 can execute arbitrary OS commands by sending a specially crafted filename to the /api/restore/download-files endpoint, related to the downloadFiles function in api/includes/restore.php.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:unitrends:enterprise_backup:*:*:*:*:*:*:*:*

Information

Published : 2017-04-19 19:59

Updated : 2017-04-24 13:21


NVD link : CVE-2017-7283

Mitre link : CVE-2017-7283


JSON object : View

CWE
CWE-20

Improper Input Validation

Advertisement

dedicated server usa

Products Affected

unitrends

  • enterprise_backup