Vulnerabilities > Qnap > Photo Station

DATE CVE VULNERABILITY TITLE RISK
2020-11-02 CVE-2018-19954 Cross-site Scripting vulnerability in Qnap Photo Station
The cross-site scripting vulnerability has been reported to affect earlier versions of Photo Station.
network
low complexity
qnap CWE-79
6.1
2019-12-05 CVE-2019-7195 Path Traversal vulnerability in Qnap Photo Station
This external control of file name or path vulnerability allows remote attackers to access or modify system files.
network
low complexity
qnap CWE-22
7.5
2019-12-05 CVE-2019-7194 Path Traversal vulnerability in Qnap Photo Station
This external control of file name or path vulnerability allows remote attackers to access or modify system files.
network
low complexity
qnap CWE-22
7.5
2019-12-05 CVE-2019-7192 Incorrect Authorization vulnerability in Qnap Photo Station
This improper access control vulnerability allows remote attackers to gain unauthorized access to the system.
network
low complexity
qnap CWE-863
7.5
2019-02-01 CVE-2018-0722 Path Traversal vulnerability in Qnap Photo Station
Path Traversal vulnerability in Photo Station versions: 5.7.2 and earlier in QTS 4.3.4, 5.4.4 and earlier in QTS 4.3.3, 5.2.8 and earlier in QTS 4.2.6 could allow remote attackers to access sensitive information on the device.
network
low complexity
qnap CWE-22
5.0
2018-08-27 CVE-2018-0715 Cross-site Scripting vulnerability in Qnap Photo Station
Cross-site scripting vulnerability in QNAP Photo Station versions 5.7.0 and earlier could allow remote attackers to inject Javascript code in the compromised application.
network
qnap CWE-79
4.3
2018-04-23 CVE-2017-13073 Cross-site Scripting vulnerability in Qnap Photo Station
Cross-site scripting (XSS) vulnerability in QNAP NAS application Photo Station versions 5.2.7, 5.4.3, and their earlier versions could allow remote attackers to inject arbitrary web script or HTML.
network
qnap CWE-79
4.3
2014-06-09 CVE-2013-5760 Information Exposure vulnerability in Qnap Photo Station and Photo Station Firmware
QNAP Photo Station before firmware 4.0.3 build0912 allows remote attackers to list OS user accounts via a request to photo/p/api/list.php.
network
low complexity
qnap CWE-200
5.0