RSS   Vulnerabilities for 'Photo station'   RSS

2022-05-05
 
CVE-2021-44057

CWE-287
 

 
An improper authentication vulnerability has been reported to affect QNAP device running Photo Station. If exploited, this vulnerability allows attackers to compromise the security of the system. We have already fixed this vulnerability in the following versions of Photo Station: Photo Station 6.0.20 ( 2022/02/15 ) and later Photo Station 5.7.16 ( 2022/02/11 ) and later Photo Station 5.4.13 ( 2022/02/11 ) and later

 
2021-02-17
 
CVE-2020-2502

CWE-79
 

 
This cross-site scripting vulnerability in Photo Station allows remote attackers to inject malicious code. QANP We have already fixed this vulnerability in the following versions of Photo Station. Photo Station 6.0.11 and later

 
2020-11-02
 
CVE-2018-19956

CWE-79
 

 
The cross-site scripting vulnerability has been reported to affect earlier versions of Photo Station. If exploited, the vulnerability could allow remote attackers to inject malicious code. This issue affects: QNAP Systems Inc. Photo Station versions prior to 5.7.11; versions prior to 6.0.10.

 
 
CVE-2018-19955

CWE-79
 

 
The cross-site scripting vulnerability has been reported to affect earlier versions of Photo Station. If exploited, the vulnerability could allow remote attackers to inject malicious code. This issue affects: QNAP Systems Inc. Photo Station versions prior to 5.7.11; versions prior to 6.0.10.

 
 
CVE-2018-19954

CWE-79
 

 
The cross-site scripting vulnerability has been reported to affect earlier versions of Photo Station. If exploited, the vulnerability could allow remote attackers to inject malicious code. This issue affects: QNAP Systems Inc. Photo Station versions prior to 5.7.11; versions prior to 6.0.10.

 
2019-02-01
 
CVE-2018-0722

CWE-22
 

 
Path Traversal vulnerability in Photo Station versions: 5.7.2 and earlier in QTS 4.3.4, 5.4.4 and earlier in QTS 4.3.3, 5.2.8 and earlier in QTS 4.2.6 could allow remote attackers to access sensitive information on the device.

 
2018-08-27
 
CVE-2018-0715

CWE-79
 

 
Cross-site scripting vulnerability in QNAP Photo Station versions 5.7.0 and earlier could allow remote attackers to inject Javascript code in the compromised application.

 
2014-06-09
 
CVE-2013-5760

CWE-200
 

 
QNAP Photo Station before firmware 4.0.3 build0912 allows remote attackers to list OS user accounts via a request to photo/p/api/list.php.

 

 >>> Vendor: QNAP 41 Products
Ts-239 pro turbo nas
Ts-639 pro turbo nas
Surveillance station pro
NAS
Viostor network video recorder
QTS
Photo station
Photo station firmware
Ss-839
Ts-459u
Ts-469u
Ts-ec1679u-rp
Ss-839 firmware
Ts-459u firmware
Ts-469u firmware
Ts-ec1679u-rp firmware
Sinage station
Signage station
Iartist lite
Ts-212p firmware
Qts helpdesk
Music station
Video station
Qsync
Media streaming add-on
Qfinder pro
Q'center
Helpdesk
Q'center virtual appliance
Myqnapcloud
Netbak replicator
Quts hero
Multimedia console
QES
Qutscloud
Roon server
Qulog center
Q\'center
QVR
Qcalagent
Qvr firmware


Copyright 2024, cxsecurity.com

 

Back to Top