vendor:
Bacula-Web
by:
Gustavo Sorondo
9.8
CVSS
CRITICAL
SQL Injection
89
CWE
Product Name: Bacula-Web
Affected Version From: Before 8.0.0-rc2
Affected Version To: Before 8.0.0-rc2
Patch Exists: YES
Related CWE: CVE-2017-15367
CPE: a:bacula-web:bacula-web
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Webapps
2018
Multiple SQL injection vulnerabilities in Bacula-Web
Bacula-web before 8.0.0-rc2 is affected by multiple SQL Injection vulnerabilities that could allow an attacker to access the Bacula database and, depending on configuration, escalate privileges on the server.
Mitigation:
Update to version 8.0.0-RC2