VYPR

BDR

by Vembu

CVEs (3)

  • CVE-2021-26471Jun 8, 2021
    risk 0.01cvss epss 0.02

    In VembuBDR before 4.2.0.1 and VembuOffsiteDR before 4.2.0.1, the http API located at /sgwebservice_o.php accepts a command argument. Using this command argument an unauthenticated attacker can execute arbitrary shell commands.

  • CVE-2021-43458Apr 4, 2022
    risk 0.00cvss epss 0.00

    An Unquoted Service Path vulnerability exits in Vembu BDR 4.2.0.1 via a specially crafted file in the (1) hsflowd, (2) VembuBDR360Agent, or (3) VembuOffice365Agent service paths.

  • CVE-2021-26473Jun 8, 2021
    risk 0.00cvss epss 0.02

    In VembuBDR before 4.2.0.1 and VembuOffsiteDR before 4.2.0.1 the http API located at /sgwebservice_o.php action logFilePath allows an attacker to write arbitrary files in the context of the web server process. These files can then be executed remotely by calling the file via the…