Qnap Systems QCenter是中国威联通(Qnap Systems)公司的一个中央管理平台,可让您整合多个 QNAP NAS 的管理。 QNAP Qcenter 中存在跨站脚本漏洞,该漏洞源于产品缺少对用户数据进行安全验证,攻击者可通过该漏洞执行客户端代码。以下产品及版本受到影响:QNAP Qcenter 1.11.1004 版本及之前的版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| QNAP Systems Inc. | Q'center | unspecified ~ 1.11.1004 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2020-36194 | 6.1 MEDIUM | XSS Vulnerability in QTS and QuTS heroCommand Injection Vulnerabilities in QTS and QuTS he |
| CVE-2021-28804 | Command Injection Vulnerabilities in QTS and QuTS hero | |
| CVE-2021-28802 | Command Injection Vulnerabilities in QTS and QuTS hero | |
| CVE-2020-36196 | Stored XSS Vulnerability in QuLog Center |
No comments yet