Quantcast
Channel: Files from Valentin Lobstein ≈ Packet Storm
Viewing all articles
Browse latest Browse all 33

Vinchin Backup And Recovery Command Injection

$
0
0
This Metasploit module exploits a command injection vulnerability in Vinchin Backup & Recovery v5.0.*, v6.0.*, v6.7.*, and v7.0.*. Due to insufficient input validation in the checkIpExists API endpoint, an attacker can execute arbitrary commands as the web server user.

Viewing all articles
Browse latest Browse all 33

Trending Articles