ASUSTOR Data Master(ADM)是华芸科技(ASUSTOR)公司的一套专用于ASUSTOR NAS存储设备的操作系统。 ADM 3.1.5及之前版本中存在跨站脚本漏洞,该漏洞源于程序将HTTP请求用于配置文件。远程攻击者可通过实施中间人攻击利用该漏洞将Javascript代码注入配置文件的版本字段,进而窃取管理员凭证。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Tenable | ASUSTOR Data Master | 3.1.5 and below | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2018-15694 | ASUSTOR Data Master 路径遍历漏洞 | |
| CVE-2018-15695 | ASUSTOR Data Master 路径遍历漏洞 | |
| CVE-2018-15696 | ASUSTOR Data Master 安全漏洞 | |
| CVE-2018-15697 | ASUSTOR Data Master 安全漏洞 | |
| CVE-2018-15698 | ASUSTOR Data Master 安全漏洞 |
No comments yet