漏洞描述 Dell NetVault Backup是美国戴尔(Dell)公司的一套跨平台备份和恢复软件解决方案。该方案可保护物理和虚拟环境中的数据和应用程序。 Dell NetVault Backup 10.0.5之前版本的libnv6模块中存在远程代码执行漏洞。攻击者可借助序列化对象中的模版字符串说明符利用该漏洞在系统上下文中执行任意代码。
相关漏洞推荐 POC generic-php-files: Generic PHP Backup Information Disclosure backup-files: Compressed Backup File - Detect POC CVE-2014-9119: WordPress DB Backup <=4.5 - Local File Inclusion POC CVE-2020-24312: WordPress Plugin File Manager (wp-file-manager) Backup Disclosure POC CVE-2021-24155: WordPress BackupGuard <1.6.0 - Authenticated Arbitrary File Upload POC CVE-2022-2863: WordPress WPvivid Backup <0.9.76 - Local File Inclusion POC CVE-2022-31474: BackupBuddy - Local File Inclusion POC CVE-2022-4897: WordPress BackupBuddy <8.8.3 - Cross Site Scripting POC CVE-2023-6553: Worpress Backup Migration <= 1.3.7 - Unauthenticated Remote Code Execution POC CVE-2024-12209: WP Umbrella Update Backup Restore & Monitoring <= 2.17.0 - Local File Inclusion POC CVE-2024-48248: NAKIVO Backup and Replication Solution - Unauthenticated Arbitrary File Read POC CVE-2024-53991: Discourse Backup File Disclosure Via Default Nginx Configuration POC CVE-2025-5961: WordPress WPvivid Backup & Migration Plugin <= 0.9.116 - Authenticated Arbitrary File Upload