Page 18 of 115 results (0.014 seconds)

CVSS: 9.8EPSS: 0%CPEs: 3EXPL: 0

Command injection vulnerability in LDAP Server in QNAP QTS 4.2.6 build 20171208, QTS 4.3.3 build 20180402, QTS 4.3.4 build 20180413 and their earlier versions could allow remote attackers to run arbitrary commands or install malware on the NAS. Vulnerabilidad de inyección de comandos en LDAP Server en QNAP QTS 4.2.6 build 20171208, QTS 4.3.3 build 20180402, QTS 4.3.4 build 20180413 y sus versiones anteriores podría permitir que los atacantes remotos ejecuten comandos arbitrarios o instalen malware en el NAS. • http://www.securitytracker.com/id/1041141 https://www.qnap.com/zh-tw/security-advisory/nas-201806-19 • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •

CVSS: 6.1EPSS: 0%CPEs: 12EXPL: 0

Cross-site scripting (XSS) vulnerability in QNAP QTS 4.3.3 build 20180126, QTS 4.3.4 build 20180315, and their earlier versions could allow remote attackers to inject arbitrary web script or HTML. Vulnerabilidad Cross-Site Scripting (XSS) en QNAP QTS 4.3.3 build 20180126, QTS 4.3.4 build 20180315,y sus versiones anteriores, permite que los atacantes remotos inyecten scripts web o HTML arbitrarios. • http://www.securitytracker.com/id/1040779 https://www.qnap.com/zh-tw/security-advisory/nas-201804-27 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.1EPSS: 0%CPEs: 2EXPL: 0

Cross-site scripting (XSS) vulnerability in the share link function of File Station of QNAP 4.2.6 build 20171026, QTS 4.3.3 build 20170727 and earlier allows remote attackers to inject arbitrary web script or HTML. Vulnerabilidad de Cross-Site Scripting (XSS) en la función de compartición de enlaces de File Station, en QNAP 4.2.6 build 20171026, QTS 4.3.3 build 20170727 y anteriores, permite que atacantes remotos inyecten scripts web o HTML arbitrarios. • https://www.qnap.com/zh-tw/security-advisory/nas-201803-23 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.1EPSS: 0%CPEs: 2EXPL: 0

Cross-site scripting (XSS) vulnerability in File Station of QNAP QTS 4.2.6 build 20171026, QTS 4.3.3 build 20170727 and earlier allows remote attackers to inject arbitrary web script or HTML. Vulnerabilidad de Cross-Site Scripting (XSS) en File Station, en QNAP 4.2.6 build 20171026, QTS 4.3.3 build 20170727 y anteriores, permite que atacantes remotos inyecten scripts web o HTML arbitrarios. • https://www.qnap.com/zh-tw/security-advisory/nas-201803-23 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 5.3EPSS: 0%CPEs: 2EXPL: 0

QNAP QTS 4.2.6 build 20171026, QTS 4.3.3 build 20170727 and earlier allows remote attackers to obtain potentially sensitive information (firmware version and running services) via a request to sysinfoReq.cgi. QNAP QTS 4.2.6 build 20171026, QTS 4.3.3 build 20170727 y anteriores permiten que atacantes remotos obtengan información potencialmente sensible (versión de firmware y servicios en ejecución) mediante una petición en sysinfoReq.cgi. • https://www.qnap.com/zh-tw/security-advisory/nas-201803-23 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •