Show filters
21 Total Results
Displaying 11-20 of 21
Sort by:
Attacker Value
Unknown
CVE-2021-28812
Disclosure Date: June 03, 2021 (last updated February 22, 2025)
A command injection vulnerability has been reported to affect certain versions of Video Station. If exploited, this vulnerability allows remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. Video Station versions prior to 5.5.4 on QTS 4.5.2; versions prior to 5.5.4 on QuTS hero h4.5.2; versions prior to 5.5.4 on QuTScloud c4.5.4. This issue does not affect: QNAP Systems Inc. Video Station on QTS 4.3.6; on QTS 4.3.3.
0
Attacker Value
Unknown
CVE-2021-33181
Disclosure Date: May 26, 2021 (last updated February 22, 2025)
Server-Side Request Forgery (SSRF) vulnerability in webapi component in Synology Video Station before 2.4.10-1632 allows remote authenticated users to send arbitrary request to intranet resources via unspecified vectors.
0
Attacker Value
Unknown
CVE-2019-7184
Disclosure Date: December 05, 2019 (last updated November 27, 2024)
This cross-site scripting (XSS) vulnerability in Video Station allows remote attackers to inject and execute scripts on the administrator’s management console. To fix this vulnerability, QNAP recommend updating Video Station to their latest versions.
0
Attacker Value
Unknown
CVE-2017-13071
Disclosure Date: November 22, 2017 (last updated November 26, 2024)
QNAP has already patched this vulnerability. This security concern allows a remote attacker to run arbitrary commands on the QNAP Video Station 5.1.3 (for QTS 4.3.3), 5.2.0 (for QTS 4.3.4), and earlier.
0
Attacker Value
Unknown
CVE-2017-9556
Disclosure Date: August 11, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in Video Metadata Editor in Synology Video Station before 2.3.0-1435 allows remote authenticated attackers to inject arbitrary web script or HTML via the title parameter.
0
Attacker Value
Unknown
CVE-2015-9105
Disclosure Date: June 30, 2017 (last updated November 26, 2024)
Multiple cross-site scripting (XSS) vulnerabilities in Synology Video Station 1.2 before 1.2-0455, 1.5 before 1.5-0772, and 1.6 before 1.6-0847 allow remote authenticated attackers to inject arbitrary web script or HTML via the (1) file name or (2) collection name of videos.
0
Attacker Value
Unknown
CVE-2015-6911
Disclosure Date: September 11, 2015 (last updated October 05, 2023)
SQL injection vulnerability in Synology Video Station before 1.5-0763 allows remote attackers to execute arbitrary SQL commands via the id parameter to watchstatus.cgi.
0
Attacker Value
Unknown
CVE-2015-6910
Disclosure Date: September 11, 2015 (last updated October 05, 2023)
SQL injection vulnerability in Synology Video Station before 1.5-0757 allows remote attackers to execute arbitrary SQL commands via the id parameter to audiotrack.cgi.
0
Attacker Value
Unknown
CVE-2015-6912
Disclosure Date: September 11, 2015 (last updated October 05, 2023)
Synology Video Station before 1.5-0763 allows remote attackers to execute arbitrary shell commands via shell metacharacters in the subtitle_codepage parameter to subtitle.cgi.
0
Attacker Value
Unknown
CVE-2013-0142
Disclosure Date: June 07, 2013 (last updated October 05, 2023)
QNAP VioStor NVR devices with firmware 4.0.3, and the Surveillance Station Pro component in QNAP NAS, have a hardcoded guest account, which allows remote attackers to obtain web-server login access via unspecified vectors.
0