Vulnerabilities
Vulnerable Software
In Code42 Enterprise and Crashplan for Small Business through Client version 6.9.1, an attacker can craft a restore request to restore a file through the Code42 app to a location they do not have privileges to write.
CVSS Score
5.5
EPSS Score
0.0
Published
2019-08-21
Code42 Enterprise and Crashplan for Small Business Client version 6.7 before 6.7.5, 6.8 before 6.8.8, and 6.9 before 6.9.4 allows eval injection. A proxy auto-configuration file, crafted by a lesser privileged user, may be used to execute arbitrary code at a higher privilege as the service user.
CVSS Score
7.0
EPSS Score
0.002
Published
2019-07-19


Contact Us

Shodan ® - All rights reserved