Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown

CVE-2021-34360

Disclosure Date: May 26, 2022 (last updated February 23, 2025)
A cross-site request forgery (CSRF) vulnerability has been reported to affect QNAP device running Proxy Server. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Proxy Server: QTS 4.5.x: Proxy Server 1.4.2 ( 2021/12/30 ) and later QuTS hero h5.0.0: Proxy Server 1.4.3 ( 2022/01/18 ) and later QuTScloud c4.5.6: Proxy Server 1.4.2 ( 2021/12/30 ) and later
Attacker Value
Unknown

CVE-2021-34359

Disclosure Date: February 24, 2022 (last updated February 23, 2025)
A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Proxy Server. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Proxy Server: QTS 4.5.x: Proxy Server 1.4.2 ( 2021/12/30 ) and later
Attacker Value
Unknown

CVE-2021-34361

Disclosure Date: February 24, 2022 (last updated February 23, 2025)
A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Proxy Server. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Proxy Server: QTS 4.5.x: Proxy Server 1.4.2 ( 2021/12/30 ) and later
Attacker Value
Unknown

CVE-2017-7639

Disclosure Date: June 05, 2018 (last updated November 26, 2024)
QNAP NAS application Proxy Server through version 1.2.0 does not authenticate requests properly. Successful exploitation can lead to change of the settings of Proxy Server.
0
Attacker Value
Unknown

CVE-2017-7635

Disclosure Date: June 05, 2018 (last updated November 26, 2024)
QNAP NAS application Proxy Server through version 1.2.0 does not utilize CSRF protections.
0
Attacker Value
Unknown

CVE-2017-7637

Disclosure Date: June 05, 2018 (last updated November 26, 2024)
QNAP NAS application Proxy Server through version 1.2.0 allows remote attackers to run arbitrary OS commands against the system with root privileges.
0
Attacker Value
Unknown

CVE-2017-7636

Disclosure Date: June 05, 2018 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in QNAP NAS application Proxy Server through version 1.2.0 allows remote attackers to inject arbitrary web script or HTML.
0