Full title: Unitrends UEB bpserverd Authentication Bypass / Remote Command Execution Exploit Category: remote exploits Platform: linux It was discovered that the api/storage web interface in Unitrends Backup (UB) before 10.0.0 has an issue in which one of its input parameters was not validated. A remote attacker could use this flaw to bypass authentication and execute arbitrary commands with root privilege on the target system. # 0day.today @ http://0day.today/