9 results (0.003 seconds)

CVSS: 5.4EPSS: 0%CPEs: 1EXPL: 0

This issue affects: QNAP Systems Inc. Q'center versions prior to 1.11.1004. Este problema afecta a: QNAP Systems Inc. Q'center versiones anteriores a 1.11.1004 • https://www.qnap.com/zh-tw/security-advisory/qsa-21-31 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) •

CVSS: 7.7EPSS: 0%CPEs: 10EXPL: 2

A post-authentication reflected XSS vulnerability has been reported to affect QNAP NAS running Q’center. If exploited, this vulnerability allows remote attackers to inject malicious code. QNAP have already fixed this vulnerability in the following versions of Q’center: QTS 4.5.3: Q’center v1.12.1012 and later QTS 4.3.6: Q’center v1.10.1004 and later QTS 4.3.3: Q’center v1.10.1004 and later QuTS hero h4.5.2: Q’center v1.12.1012 and later QuTScloud c4.5.4: Q’center v1.12.1012 and later Se ha reportado una vulnerabilidad de tipo XSS reflejada después de la autenticación que afecta los NAS de QNAP que ejecuta Q'center. Si es explotada, esta vulnerabilidad permite a atacantes remotos inyectar código malicioso. QNAP ya ha corregido esta vulnerabilidad en las siguientes versiones de Q'center: versiones QTS 4.5.3: Q'center v1.12.1012 y posteriores, versión QTS 4.3.6: Q'center v1.10.1004 y posteriores, versión QTS 4.3.3: Q'center v1.10.1004 y posteriores, versión QuTS hero h4.5.2: Q'center v1.12.1012 y posteriores, versión QuTScloud c4.5.4: Q'center v1.12.1012 y posteriores • https://www.qnap.com/zh-tw/security-advisory/qsa-21-20 https://www.shielder.it/advisories/qnap-qcenter-post-auth-remote-code-execution-via-qpkg https://www.shielder.it/advisories/qnap-qcenter-virtual-stored-xss • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 0

Cross-site scripting (XSS) vulnerability in Q'center Virtual Appliance 1.8.1014 and earlier versions could allow remote attackers to inject Javascript code in the compromised application, a different vulnerability than CVE-2018-0724. Vulnerabilidad Cross-Site Scripting (XSS) en Q'center Virtual Appliance en versiones 1.8.1014 y anteriores podría permitir que atacantes remotos inyecten código JavaScript en la aplicación comprometida. Esta vulnerabilidad es diferente de CVE-2018-0724. • https://www.qnap.com/zh-tw/security-advisory/nas-201812-26 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 0

Cross-site scripting (XSS) vulnerability in Q'center Virtual Appliance 1.8.1014 and earlier versions could allow remote attackers to inject Javascript code in the compromised application, a different vulnerability than CVE-2018-0723. Vulnerabilidad Cross-Site Scripting (XSS) en Q'center Virtual Appliance en versiones 1.8.1014 y anteriores podría permitir que atacantes remotos inyecten código JavaScript en la aplicación comprometida. Esta vulnerabilidad es diferente de CVE-2018-0723. • https://www.qnap.com/zh-tw/security-advisory/nas-201812-26 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 9.0EPSS: 4%CPEs: 1EXPL: 7

Command injection vulnerability in change password of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticated users to run arbitrary commands. Vulnerabilidad de inyección de comandos en QNAP Q'center Virtual Appliance en versiones 1.7.1063 y anteriores podría permitir que usuarios autenticados ejecuten comandos arbitrarios. QNAP Qcenter Virtual Appliance versions 1.6.1056 (20170825) and 1.6.1075 (20171123) suffer from information disclosure and command injection vulnerabilities. • https://www.exploit-db.com/exploits/45015 https://www.exploit-db.com/exploits/45043 http://packetstormsecurity.com/files/148515/QNAP-Qcenter-Virtual-Appliance-1.6.x-Information-Disclosure-Command-Injection.html http://seclists.org/fulldisclosure/2018/Jul/45 https://www.coresecurity.com/advisories/qnap-qcenter-virtual-appliance-multiple-vulnerabilities https://www.qnap.com/zh-tw/security-advisory/nas-201807-10 https://www.securityfocus.com/archive/1/542141/100/0/threaded https://seclists.org/fulldiscl • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •