漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
QTS, QuTS hero
Vulnerability Description
A command injection vulnerability has been reported to affect several QNAP operating system versions. If an attacker gains local network access who have also gained a user account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QTS 5.1.9.2954 build 20241120 and later QTS 5.2.3.3006 build 20250108 and later QuTS hero h5.1.9.2954 build 20241120 and later QuTS hero h5.2.3.3006 build 20250108 and later
CVSS Information
N/A
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Vulnerability Title
QNAP Systems QTS和QNAP Systems QuTS hero 安全漏洞
Vulnerability Description
QNAP Systems QTS和QNAP Systems QuTS hero都是中国台湾威联通科技(QNAP Systems)公司的一个具有数据存储与管理功能的软件。 QNAP Systems QTS和QNAP Systems QuTS hero存在安全漏洞,该漏洞源于存在命令注入,可能导致获得用户账户的攻击者执行任意命令。以下版本受到影响:QTS 5.1.9.2954 build 20241120之前版本、QTS 5.2.3.3006 build 20250108之前版本、QuTS hero h5.1
CVSS Information
N/A
Vulnerability Type
N/A