CVE-2017-7280: Input Validation
Published Apr 12, 2017
·Updated
An issue was discovered in api/includes/systems.php in Unitrends Enterprise Backup before 9.0.0. User input is not properly filtered before being sent to a popen function. This allows for remote code execution by sending a specially crafted user variable.
Affected Software
1 affected component
Unitrends Enterprise Backup<=8.2.0-8
Event History
Apr 12, 2017
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Data Sourced
via NVD·10:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-7280?
CVE-2017-7280 is classified as critical due to its potential for remote code execution.
2
How do I fix CVE-2017-7280?
To fix CVE-2017-7280, upgrade Unitrends Enterprise Backup to version 9.0.0 or later.
3
What systems are affected by CVE-2017-7280?
CVE-2017-7280 affects Unitrends Enterprise Backup versions up to and including 8.2.0-8.
4
What type of vulnerability is CVE-2017-7280?
CVE-2017-7280 is a remote code execution vulnerability resulting from improper user input filtering.
5
What can happen if CVE-2017-7280 is exploited?
If exploited, CVE-2017-7280 can allow an attacker to execute arbitrary code on the affected system.