QNAP Systems Photo Station是中国威联通(QNAP Systems)公司的一款照片管理和查看应用程序。 QNAP Systems Photo Station中存在访问控制错误漏洞。远程攻击者可利用该漏洞对系统进行未经授权的访问。以下产品及版本受到影响:QNAP Systems Photo Station 6.0.3之前版本(QTS 4.4.1版本),5.7.10之前版本(QTS 4.3.4版本至4.4.0版本),5.4.9之前版本(QTS 4.3.0版本至4.3.3版本),5.2.
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | QNAP NAS devices running Photo Station | QTS 4.4.1: Photo Station before version 6.0.3, QTS 4.3.4 - QTS 4.4.0: Photo Station before version 5.7.10, QTS 4.3.0 - QTS 4.3.3: Photo Station before version 5.4.9, QTS 4.2.6: Photo Station before version 5.2.11 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Checker for QNAP pre-auth root RCE (CVE-2019-7192 ~ CVE-2019-7195) | https://github.com/cycraft-corp/cve-2019-7192-check | POC Details |
| 2 | QNAP pre-auth root RCE Exploit (CVE-2019-7192 ~ CVE-2019-7195) | https://github.com/th3gundy/CVE-2019-7192_QNAP_Exploit | POC Details |
| 3 | This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix these vulnerabilities, QNAP recommend updating Photo Station to their latest versions. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2019/CVE-2019-7192.yaml | POC Details |
| 4 | None | https://github.com/chaitin/xray-plugins/blob/main/poc/manual/qnap-cve-2019-7192.yml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2019-18180 | 5.3 MEDIUM | Denial of service |
| CVE-2019-15897 | ThinkParQ BeeGFS 访问控制错误漏洞 | |
| CVE-2019-19609 | Strapi Admin面板Install and Uninstall Plugin组件输入验证错误漏洞 | |
| CVE-2019-5098 | AMD ATIDXX64.DLL 缓冲区错误漏洞 | |
| CVE-2019-19546 | Symantec Norton Password Manager 信息泄露漏洞 | |
| CVE-2019-19545 | Symantec Norton Password Manager 访问控制错误漏洞 | |
| CVE-2019-18381 | Symantec Norton Password Manager 访问控制错误漏洞 | |
| CVE-2019-17388 | Aviatrix VPN Client 安全漏洞 | |
| CVE-2019-17387 | Aviatrix VPN Client 安全漏洞 | |
| CVE-2019-7185 | QNAP Systems QNAP Music Station 跨站脚本漏洞 | |
| CVE-2019-7184 | QNAP Systems Video Station 跨站脚本漏洞 | |
| CVE-2019-7183 | QNAP Systems QNAP QTS 后置链接漏洞 | |
| CVE-2019-7195 | QNAP Systems Photo Station 路径遍历漏洞 | |
| CVE-2019-7194 | QNAP Systems Photo Station 路径遍历漏洞 | |
| CVE-2019-7193 | QNAP Systems QNAP QTS 输入验证错误漏洞 | |
| CVE-2019-19466 | SCEditor 跨站脚本漏洞 | |
| CVE-2019-19588 | validators package 资源管理错误漏洞 | |
| CVE-2019-19007 | Intelbras IWR 3000N 信息泄露漏洞 | |
| CVE-2019-19594 | PrestaShop Adobe Stock API integration 代码问题漏洞 | |
| CVE-2019-19595 | PrestaShop Adobe Stock API integration 代码问题漏洞 |
Showing top 20 of 31 CVEs. View all on vendor page → →
No comments yet