Show filters
24 Total Results
Displaying 21-24 of 24
Sort by:
Attacker Value
Unknown
CVE-2017-16770
Disclosure Date: February 27, 2018 (last updated November 26, 2024)
File and directory information exposure vulnerability in SYNO.SurveillanceStation.PersonalSettings.Photo in Synology Surveillance Station before 8.1.2-5469 allows remote authenticated users to obtain other user's sensitive files via the filename parameter.
0
Attacker Value
Unknown
CVE-2017-16767
Disclosure Date: February 27, 2018 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in User Profile in Synology Surveillance Station before 8.1.2-5469 allows remote authenticated users to inject arbitrary web script or HTML via the userDesc parameter.
0
Attacker Value
Unknown
CVE-2013-0142
Disclosure Date: June 07, 2013 (last updated October 05, 2023)
QNAP VioStor NVR devices with firmware 4.0.3, and the Surveillance Station Pro component in QNAP NAS, have a hardcoded guest account, which allows remote attackers to obtain web-server login access via unspecified vectors.
0
Attacker Value
Unknown
CVE-2013-0143
Disclosure Date: June 07, 2013 (last updated October 05, 2023)
cgi-bin/pingping.cgi on QNAP VioStor NVR devices with firmware 4.0.3, and in the Surveillance Station Pro component in QNAP NAS, allows remote authenticated users to execute arbitrary commands by leveraging guest access and placing shell metacharacters in the query string.
0