Show filters
21 Total Results
Displaying 11-20 of 21
Sort by:
Attacker Value
Unknown

CVE-2021-28812

Disclosure Date: June 03, 2021 (last updated February 22, 2025)
A command injection vulnerability has been reported to affect certain versions of Video Station. If exploited, this vulnerability allows remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. Video Station versions prior to 5.5.4 on QTS 4.5.2; versions prior to 5.5.4 on QuTS hero h4.5.2; versions prior to 5.5.4 on QuTScloud c4.5.4. This issue does not affect: QNAP Systems Inc. Video Station on QTS 4.3.6; on QTS 4.3.3.
Attacker Value
Unknown

CVE-2021-33181

Disclosure Date: May 26, 2021 (last updated February 22, 2025)
Server-Side Request Forgery (SSRF) vulnerability in webapi component in Synology Video Station before 2.4.10-1632 allows remote authenticated users to send arbitrary request to intranet resources via unspecified vectors.
Attacker Value
Unknown

CVE-2019-7184

Disclosure Date: December 05, 2019 (last updated November 27, 2024)
This cross-site scripting (XSS) vulnerability in Video Station allows remote attackers to inject and execute scripts on the administrator’s management console. To fix this vulnerability, QNAP recommend updating Video Station to their latest versions.
Attacker Value
Unknown

CVE-2017-13071

Disclosure Date: November 22, 2017 (last updated November 26, 2024)
QNAP has already patched this vulnerability. This security concern allows a remote attacker to run arbitrary commands on the QNAP Video Station 5.1.3 (for QTS 4.3.3), 5.2.0 (for QTS 4.3.4), and earlier.
0
Attacker Value
Unknown

CVE-2017-9556

Disclosure Date: August 11, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in Video Metadata Editor in Synology Video Station before 2.3.0-1435 allows remote authenticated attackers to inject arbitrary web script or HTML via the title parameter.
0
Attacker Value
Unknown

CVE-2015-9105

Disclosure Date: June 30, 2017 (last updated November 26, 2024)
Multiple cross-site scripting (XSS) vulnerabilities in Synology Video Station 1.2 before 1.2-0455, 1.5 before 1.5-0772, and 1.6 before 1.6-0847 allow remote authenticated attackers to inject arbitrary web script or HTML via the (1) file name or (2) collection name of videos.
0
Attacker Value
Unknown

CVE-2015-6911

Disclosure Date: September 11, 2015 (last updated October 05, 2023)
SQL injection vulnerability in Synology Video Station before 1.5-0763 allows remote attackers to execute arbitrary SQL commands via the id parameter to watchstatus.cgi.
0
Attacker Value
Unknown

CVE-2015-6910

Disclosure Date: September 11, 2015 (last updated October 05, 2023)
SQL injection vulnerability in Synology Video Station before 1.5-0757 allows remote attackers to execute arbitrary SQL commands via the id parameter to audiotrack.cgi.
0
Attacker Value
Unknown

CVE-2015-6912

Disclosure Date: September 11, 2015 (last updated October 05, 2023)
Synology Video Station before 1.5-0763 allows remote attackers to execute arbitrary shell commands via shell metacharacters in the subtitle_codepage parameter to subtitle.cgi.
0
Attacker Value
Unknown

CVE-2013-0142

Disclosure Date: June 07, 2013 (last updated October 05, 2023)
QNAP VioStor NVR devices with firmware 4.0.3, and the Surveillance Station Pro component in QNAP NAS, have a hardcoded guest account, which allows remote attackers to obtain web-server login access via unspecified vectors.
0