Page 16 of 103 results (0.009 seconds)

CVSS: 6.1EPSS: 0%CPEs: 2EXPL: 0

Cross-site scripting (XSS) vulnerability in the share link function of File Station of QNAP 4.2.6 build 20171026, QTS 4.3.3 build 20170727 and earlier allows remote attackers to inject arbitrary web script or HTML. Vulnerabilidad de Cross-Site Scripting (XSS) en la función de compartición de enlaces de File Station, en QNAP 4.2.6 build 20171026, QTS 4.3.3 build 20170727 y anteriores, permite que atacantes remotos inyecten scripts web o HTML arbitrarios. • https://www.qnap.com/zh-tw/security-advisory/nas-201803-23 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.1EPSS: 0%CPEs: 2EXPL: 0

Cross-site scripting (XSS) vulnerability in File Station of QNAP QTS 4.2.6 build 20171026, QTS 4.3.3 build 20170727 and earlier allows remote attackers to inject arbitrary web script or HTML. Vulnerabilidad de Cross-Site Scripting (XSS) en File Station, en QNAP 4.2.6 build 20171026, QTS 4.3.3 build 20170727 y anteriores, permite que atacantes remotos inyecten scripts web o HTML arbitrarios. • https://www.qnap.com/zh-tw/security-advisory/nas-201803-23 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 5.3EPSS: 0%CPEs: 2EXPL: 0

QNAP QTS 4.2.6 build 20171026, QTS 4.3.3 build 20170727 and earlier allows remote attackers to obtain potentially sensitive information (firmware version and running services) via a request to sysinfoReq.cgi. QNAP QTS 4.2.6 build 20171026, QTS 4.3.3 build 20170727 y anteriores permiten que atacantes remotos obtengan información potencialmente sensible (versión de firmware y servicios en ejecución) mediante una petición en sysinfoReq.cgi. • https://www.qnap.com/zh-tw/security-advisory/nas-201803-23 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 10.0EPSS: 0%CPEs: 4EXPL: 0

QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier allows remote attackers to run arbitrary OS commands against the system with root privileges. El add-on Media Streaming de la aplicación NAS de QNAP en versiones 421.1.0.2, 430.1.2.0 y anteriores permite que los atacantes remotos ejecuten comandos arbitrarios del sistema operativo contra el sistema con privilegios root. • https://www.qnap.com/zh-tw/security-advisory/nas-201803-08 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •

CVSS: 6.5EPSS: 0%CPEs: 4EXPL: 0

QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier does not authenticate requests properly. Successful exploitation could lead to change of the Media Streaming settings, and leakage of sensitive information of the QNAP NAS. El add-on Media Streaming de la aplicación NAS de QNAP en versiones 421.1.0.2, 430.1.2.0 y anteriores no autentica las peticiones correctamente. Su explotación exitosa podría provocar que se cambie la configuración de Media Streaming y que se fugue información sensible del NAS de QNAP. • https://www.qnap.com/zh-tw/security-advisory/nas-201803-08 • CWE-287: Improper Authentication •