# Unitrends Enterprise Backup Local File Inclusion  
[CVE-2017-7282]

## Vulnerability Details

CVSS Rating: 5.5 (medium)

### CVE-2017-7282

**Disclosing Company:** Rhino Security Labs  
**Date:** 04/19/2017  
**Status:** Published  
**Affected software/version:**  
Unitrends Enterprise Backup < 9.1.1

## Disclosure

### Rhino Security Labs References

[Blog Post: "UNITRENDS VULNERABILITY HUNTING: REMOTE CODE EXECUTION"](/content/research/remote-code-execution-bug-hunting-chapter-2/index.html)  
[GitHub: LFI for Unitrends 9.0 Exploit](https://github.com/RhinoSecurityLabs/Security-Research/tree/master/exploits/Unitrends/CVE-2017-7282-LFI)  
[Unitrends: Unitrends LFI in restore.php filename](https://support.unitrends.com/UnitrendsBackup/s/article/000005558?r=1)  
[MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7282)  
[NIST](https://nvd.nist.gov/vuln/detail/CVE-2017-7282)

### Disclosure Date

04/19/2017

### Vulnerability Description

An issue was discovered in Unitrends Enterprise Backup before 9.1.1. The function downloadFile in api/includes/restore.php blindly accepts any filename passed to /api/restore/download as valid. This allows an authenticated attacker to read any file in the filesystem that the web server has access to, aka Local File Inclusion (LFI).

### Related Disclosures

[Unitrends Enterprise Backup Privilege Escalation in Token Cookie  
[CVE-2017-7279]](/content/vulnerability-disclosure/unitrends-enterprise-backup-privilege-escalation-in-token-cookie/index.html)  
[Unitrends Enterprise Backup Privilege Escalation in users.php File  
[CVE-2017-7284]](/content/vulnerability-disclosure/unitrends-enterprise-backup-privilege-escalation-in-users-php-file/index.html)  
[Unitrends Enterprise Backup Remote Code Execution in systems.php File  
[CVE-2017-7280]](/content/vulnerability-disclosure/unitrends-enterprise-backup-remote-code-execution-in-systems-php-file/index.html)  
[Unitrends Enterprise Backup Remote Code Execution in reports.php File  
[CVE-2017-7281]](/content/vulnerability-disclosure/unitrends-enterprise-backup-remote-code-execution-in-reports-php-file/index.html)  
[Unitrends Enterprise Backup Remote Code Execution in restore.php File  
[CVE-2017-7283]](/content/vulnerability-disclosure/unitrends-enterprise-backup-remote-code-execution-in-restore-php-file/index.html)

## CVSS Metrics

### CVSS Rating (version 3.0)

**5.5 (Medium)**

### Impact Score

### Exploitability Score

3.6

1.8

### Attack Vector

Local File Inclusion

**Attack Complexity (AC)** Low  
**Privileges Required (PR)** None  
**User Interaction (UI)** Required  
**Scope (S)** Unchanged

**Confidentiality (C)** High  
**Integrity (I)** None  
**Availability (A)** None
