VU#927644Third-party advisory
http://www.kb.cert.org/vuls/id/927644 CVE-2013-0143
QNAP VioStor NVR / QNAP NAS - Remote Code Execution
Record summary
CVE-2013-0143 has a selected CVSS score of 6.5; EIP currently links 1 catalogued exploit.
Description
cgi-bin/pingping.cgi on QNAP VioStor NVR devices with firmware 4.0.3, and in the Surveillance Station Pro component in QNAP NAS, allows remote authenticated users to execute arbitrary commands by leveraging guest access and placing shell metacharacters in the query string.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBQNAP VioStor NVR / QNAP NAS - Remote Code ExecutionExploitDB exploitby Tim HerresNot analyzed1 file
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2013-0143