RSS   Vulnerabilities for 'Viostor network video recorder'   RSS

2013-06-07
 
CVE-2013-0144

CWE-352
 

 
Cross-site request forgery (CSRF) vulnerability in cgi-bin/create_user.cgi on QNAP VioStor NVR devices with firmware 4.0.3 allows remote attackers to hijack the authentication of administrators for requests that create administrative accounts via a NEW USER action.

 
 
CVE-2013-0143

CWE-94
 

 
cgi-bin/pingping.cgi on QNAP VioStor NVR devices with firmware 4.0.3, and in the Surveillance Station Pro component in QNAP NAS, allows remote authenticated users to execute arbitrary commands by leveraging guest access and placing shell metacharacters in the query string.

 
 
CVE-2013-0142

CWE-255
 

 
QNAP VioStor NVR devices with firmware 4.0.3, and the Surveillance Station Pro component in QNAP NAS, have a hardcoded guest account, which allows remote attackers to obtain web-server login access via unspecified vectors.

 

 >>> Vendor: QNAP 41 Products
NAS
Helpdesk
Ts-239 pro turbo nas
Ts-639 pro turbo nas
Surveillance station pro
Viostor network video recorder
QTS
Photo station
Photo station firmware
Ss-839
Ts-459u
Ts-469u
Ts-ec1679u-rp
Ss-839 firmware
Ts-459u firmware
Ts-469u firmware
Ts-ec1679u-rp firmware
Video station
Sinage station
Signage station
Iartist lite
Ts-212p firmware
Qts helpdesk
Music station
Qsync
Media streaming add-on
Qfinder pro
Q'center
Q'center virtual appliance
Myqnapcloud
Netbak replicator
Quts hero
Multimedia console
QES
Qutscloud
Roon server
Qulog center
Q\'center
QVR
Qcalagent
Qvr firmware


Copyright 2024, cxsecurity.com

 

Back to Top