Vulnerabilities > Vembu > Offsite DR > Critical

DATE CVE VULNERABILITY TITLE RISK
2021-06-08 CVE-2021-26473 Unrestricted Upload of File with Dangerous Type vulnerability in Vembu BDR Suite and Offsite DR
In VembuBDR before 4.2.0.1 and VembuOffsiteDR before 4.2.0.1 the http API located at /sgwebservice_o.php action logFilePath allows an attacker to write arbitrary files in the context of the web server process.
network
low complexity
vembu CWE-434
critical
9.8
2021-06-08 CVE-2021-26472 OS Command Injection vulnerability in Vembu BDR Suite and Offsite DR
In VembuBDR before 4.2.0.1 and VembuOffsiteDR before 4.2.0.1 installed on Windows, the http API located at /consumerweb/secure/download.php.
network
low complexity
vembu CWE-78
critical
9.8
2021-06-08 CVE-2021-26471 Unspecified vulnerability in Vembu BDR Suite and Offsite DR
In VembuBDR before 4.2.0.1 and VembuOffsiteDR before 4.2.0.1, the http API located at /sgwebservice_o.php accepts a command argument.
network
low complexity
vembu
critical
9.8