Page 2 of 8 results (0.005 seconds)

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 1

VinChin Backup & Recovery v5.0.*, v6.0.*, v6.7.*, and v7.0.* was discovered to contain a command injection vulnerability. Se descubrió que VinChin Backup & Recovery v5.0.*, v6.0.*, v6.7.* y v7.0.* contiene una vulnerabilidad de inyección de comandos. • http://packetstormsecurity.com/files/175397/VinChin-VMWare-Backup-7.0-Hardcoded-Credential-Remote-Code-Execution.html http://packetstormsecurity.com/files/176289/Vinchin-Backup-And-Recovery-Command-Injection.html http://seclists.org/fulldisclosure/2023/Oct/31 https://blog.leakix.net/2023/10/vinchin-backup-rce-chain https://vinchin.com • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 1

VinChin Backup & Recovery v5.0.*, v6.0.*, v6.7.*, and v7.0.* was discovered to contain hardcoded credentials. Se descubrió que VinChin Backup & Recovery v5.0.*, v6.0.*, v6.7.* y v7.0.* contenía credenciales codificadas. • http://packetstormsecurity.com/files/175397/VinChin-VMWare-Backup-7.0-Hardcoded-Credential-Remote-Code-Execution.html http://packetstormsecurity.com/files/176289/Vinchin-Backup-And-Recovery-Command-Injection.html http://seclists.org/fulldisclosure/2023/Oct/31 https://blog.leakix.net/2023/10/vinchin-backup-rce-chain https://vinchin.com • CWE-798: Use of Hard-coded Credentials •

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 0

This vulnerability allows remote attackers to bypass authentication on affected installations of Vinchin Backup and Recovery 6.5.0.17561. Authentication is not required to exploit this vulnerability. The specific flaw exists within the configuration of the MySQL server. The server uses a hard-coded password for the administrator user. An attacker can leverage this vulnerability to bypass authentication on the system. • http://packetstormsecurity.com/files/176794/Vinchin-Backup-And-Recovery-7.2-Default-MySQL-Credentials.html http://seclists.org/fulldisclosure/2024/Jan/30 https://www.zerodayinitiative.com/advisories/ZDI-22-959 • CWE-798: Use of Hard-coded Credentials •