Show filters
14 Total Results
Displaying 11-14 of 14
Sort by:
Attacker Value
Unknown

CVE-2019-7185

Disclosure Date: December 05, 2019 (last updated November 27, 2024)
This cross-site scripting (XSS) vulnerability in Music Station allows remote attackers to inject and execute scripts on the administrator’s management console. To fix this vulnerability, QNAP recommend updating Music Station to their latest versions.
Attacker Value
Unknown

CVE-2018-0729

Disclosure Date: December 04, 2019 (last updated November 27, 2024)
This command injection vulnerability in Music Station allows attackers to execute commands on the affected device. To fix the vulnerability, QNAP recommend updating Music Station to their latest versions.
Attacker Value
Unknown

CVE-2018-0718

Disclosure Date: September 14, 2018 (last updated November 27, 2024)
Command injection vulnerability in Music Station 5.1.2 and earlier versions in QNAP QTS 4.3.3 and 4.3.4 could allow remote attackers to run arbitrary commands in the compromised application.
0
Attacker Value
Unknown

CVE-2017-13069

Disclosure Date: October 06, 2017 (last updated November 26, 2024)
QNAP discovered a number of command injection vulnerabilities found in Music Station versions 4.8.6 (for QTS 4.2.x), 5.0.7 (for QTS 4.3.x), and earlier. If exploited, these vulnerabilities may allow a remote attacker to run arbitrary commands on the NAS.
0