QNAP Systems Photo Station是中国威联通(QNAP Systems)公司的一款照片管理和查看应用程序。 QNAP Systems Photo Station 6.0.20、5.7.16、4.5.13 之前版本存在授权问题漏洞,该漏洞源于处理身份验证请求时出错。远程攻击者利用此漏洞可绕过身份验证过程,危及系统安全。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| QNAP Systems Inc. | Photo Station | unspecified ~ 6.0.20 ( 2022/02/15 ) | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-27588 | 9.8 CRITICAL | Vulnerability in QVR |
| CVE-2021-44051 | 8.8 HIGH | Command injection |
| CVE-2021-44056 | 7.1 HIGH | Improper authentication in Video Station |
| CVE-2021-44052 | 6.5 MEDIUM | Arbitrary file read |
| CVE-2021-44053 | 5.7 MEDIUM | Reflected XSS |
| CVE-2021-38693 | 5.3 MEDIUM | Path Traversal in thttpd |
| CVE-2021-44055 | 5.3 MEDIUM | Information leakage in Video Station |
| CVE-2021-44054 | 4.3 MEDIUM | Open redirect |
No comments yet