# Unitrends Enterprise Backup Remote Code Execution in reports.php File  
[CVE-2017-7281]

## Vulnerability Details

CVSS Rating: 8.8 (high)

### CVE-2017-7281

**Disclosing Company:** Rhino Security Labs  
**Date:** 04/12/2017  
**Status:** Published

**Affected software/version:**  
Unitrends Enterprise Backup < 9.1.2

## Disclosure

### Rhino Security Labs References

[Blog Post: "UNITRENDS VULNERABILITY HUNTING: REMOTE CODE EXECUTION"](/content/research/remote-code-execution-bug-hunting-chapter-1/index.html)  
[GitHub: CVE-2017-7281-RCE-File-Upload Exploit](https://github.com/RhinoSecurityLabs/Security-Research/tree/master/exploits/Unitrends/CVE-2017-7281-RCE-File-Upload)  
[Unitrends: "Unitrends unrestricted report file upload"](https://support.unitrends.com/UnitrendsBackup/s/article/000005559)  
[MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7281)  
[NIST](https://nvd.nist.gov/vuln/detail/CVE-2017-7281)

### Disclosure Date

04/12/2017

### Vulnerability Description

An issue was discovered in Unitrends Enterprise Backup before 9.1.2. A lack of sanitization of user input in the createReportName and saveReport functions in recoveryconsole/bpl/reports.php allows for an authenticated user to create a randomly named file on disk with a user-controlled extension, contents, and path, leading to remote code execution, aka Unrestricted File Upload.

### Related Disclosures

[Unitrends Enterprise Backup Remote Code Execution in restore.php File\[CVE-2017-7283\]](/content/vulnerability-disclosure/unitrends-enterprise-backup-remote-code-execution-in-restore-php-file/index.html)  
[Unitrends Enterprise Backup Remote Code Execution in systems.php File\[CVE-2017-7280\]](/content/vulnerability-disclosure/unitrends-enterprise-backup-remote-code-execution-in-systems-php-file/index.html)  
[Unitrends Enterprise Backup Privilege Escalation in users.php File\[CVE-2017-7284\]](/content/vulnerability-disclosure/unitrends-enterprise-backup-privilege-escalation-in-users-php-file/index.html)  
[Unitrends Enterprise Backup Privilege Escalation in Token Cookie\[CVE-2017-7279\]](/content/vulnerability-disclosure/unitrends-enterprise-backup-privilege-escalation-in-token-cookie/index.html)  
[Unitrends Enterprise Backup Local File Inclusion\[CVE-2017-7282\]](/content/vulnerability-disclosure/unitrends-enterprise-backup-local-file-inclusion/index.html)

## CVSS Metrics

### CVSS Rating (version 3.0)

**8.8 (High)**

### Impact Score

### Exploitability Score

5.9

2.8

### Attack Vector

Network

**Attack Complexity (AC)** Low  
**Privileges Required (PR)** Low  
**User Interaction (UI)** None  
**Scope (S)** Unchanged

**Confidentiality (C)** High  
**Integrity (I)** High  
**Availability (A)** High
