← Back

Backup

backup

Vendor: Unitrends • 2 CVEs

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Unitrends
1Backup
Nov 21, 2024
Feb 17, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In Unitrends Backup before 10.4.1, an HTTP request parameter was not properly sanitized, allowing for SQL injection that resulted in an authentication bypass.
1Unitrends
1Backup
Nov 21, 2024
Mar 14, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
It was discovered that the Unitrends Backup (UB) before 10.1.0 libbpext.so authentication could be bypassed with a SQL injection, allowing a remote attacker to place a privilege escalation exploit on the target system an...Show more
It was discovered that the Unitrends Backup (UB) before 10.1.0 libbpext.so authentication could be bypassed with a SQL injection, allowing a remote attacker to place a privilege escalation exploit on the target system and subsequently execute arbitrary commands.Show less