CVE-2021-39392

critical

Description

The management tool in MyLittleBackup up to and including 1.7 allows remote attackers to execute arbitrary code because machineKey is hardcoded (the same for all customers' installations) in web.config, and can be used to send serialized ASP code.

References

https://gist.github.com/omriinbar/65827626e63f15e3e50557e2d9d61281

http://www.mylittlebackup.com/mlb/zip/mlb_1.7.zip

Details

Source: Mitre, NVD

Published: 2021-09-15

Updated: 2021-10-07

Risk Information

CVSS v2

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Severity: High

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical