CVE-2018-6329
critical · 9.8It was discovered that the Unitrends Backup (UB) before 10.1.0 libbpext.so authentication could be bypassed with a SQL injection, allowing a remote attacker to place a privilege escalation exploit on the target system and subsequently execute arbitrary commands.
9.8
CVSS
61.2%
EPSS (exploit prob.)
99th
EPSS percentile
2018-03-14
Published
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-89
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| unitrends | backup | < 10.1.10 |
Check a specific version with /api/v1/cve/match.
References
- https://support.unitrends.com/UnitrendsBackup/s/article/000001150
- https://support.unitrends.com/UnitrendsBackup/s/article/000006003
- https://www.exploit-db.com/exploits/44297/
- https://www.exploit-db.com/exploits/45913/
- https://support.unitrends.com/UnitrendsBackup/s/article/000001150
- https://support.unitrends.com/UnitrendsBackup/s/article/000006003
- https://www.exploit-db.com/exploits/44297/
- https://www.exploit-db.com/exploits/45913/
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2018-6329