Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Command Injection Vulnerability in QVR
Vulnerability Description
A command injection vulnerability has been reported to affect QNAP device running QVR. If exploited, this vulnerability could allow remote attackers to run arbitrary commands. We have already fixed this vulnerability in the following versions of QVR: QVR 5.1.5 build 20210902 and later
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Vulnerability Title
Qnap Qvr 命令注入漏洞
Vulnerability Description
Qnap Qvr是中国威联通科技(Qnap)公司的一个Qnap监控系统控制中心。 Qnap Qvr 5.1.5 build 20210902 之前版本存在命令注入漏洞,远程攻击者可利用该漏洞运行任意命令。
CVSS Information
N/A
Vulnerability Type
N/A