Vulnerabilities > Qsan
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-08-02 | CVE-2021-37216 | Cross-site Scripting vulnerability in Qsan Xn8008T Firmware and Xn8024R Firmware QSAN Storage Manager header page parameters does not filter special characters. | 6.1 |
2021-07-07 | CVE-2021-32506 | Path Traversal vulnerability in Qsan Storage Manager Absolute Path Traversal vulnerability in GetImage in QSAN Storage Manager allows remote authenticated attackers download arbitrary files via the Url path parameter. | 6.5 |
2021-07-07 | CVE-2021-32507 | Path Traversal vulnerability in Qsan Storage Manager Absolute Path Traversal vulnerability in FileDownload in QSAN Storage Manager allows remote authenticated attackers download arbitrary files via the Url path parameter. | 6.5 |
2021-07-07 | CVE-2021-32508 | Link Following vulnerability in Qsan Storage Manager Absolute Path Traversal vulnerability in FileStreaming in QSAN Storage Manager allows remote authenticated attackers access arbitrary files by injecting the Symbolic Link following the Url path parameter. | 6.5 |
2021-07-07 | CVE-2021-32509 | Link Following vulnerability in Qsan Storage Manager Absolute Path Traversal vulnerability in FileviewDoc in QSAN Storage Manager allows remote authenticated attackers access arbitrary files by injecting the Symbolic Link following the Url path parameter. | 6.5 |
2021-07-07 | CVE-2021-32510 | Information Exposure Through Directory Listing vulnerability in Qsan Storage Manager QSAN Storage Manager through directory listing vulnerability in antivirus function allows remote authenticated attackers to list arbitrary directories by injecting file path parameter. | 4.3 |
2021-07-07 | CVE-2021-32511 | Information Exposure Through Directory Listing vulnerability in Qsan Storage Manager QSAN Storage Manager through directory listing vulnerability in ViewBroserList allows remote authenticated attackers to list arbitrary directories via the file path parameter. | 4.3 |
2021-07-07 | CVE-2021-32512 | OS Command Injection vulnerability in Qsan Storage Manager QuickInstall in QSAN Storage Manager does not filter special parameters properly that allows remote unauthenticated attackers to inject and execute arbitrary commands. | 9.8 |
2021-07-07 | CVE-2021-32513 | OS Command Injection vulnerability in Qsan Storage Manager QsanTorture in QSAN Storage Manager does not filter special parameters properly that allows remote unauthenticated attackers to inject and execute arbitrary commands. | 9.8 |
2021-07-07 | CVE-2021-32514 | Unspecified vulnerability in Qsan Storage Manager Improper access control vulnerability in FirmwareUpgrade in QSAN Storage Manager allows remote attackers to reboot and discontinue the device. | 7.5 |