Vulnerabilities > Qsan > Storage Manager
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-07-07 | CVE-2021-32506 | Absolute Path Traversal vulnerability in Qsan Storage Manager Absolute Path Traversal vulnerability in GetImage in QSAN Storage Manager allows remote authenticated attackers download arbitrary files via the Url path parameter. | 4.0 |
2021-07-07 | CVE-2021-32507 | Path Traversal vulnerability in Qsan Storage Manager Absolute Path Traversal vulnerability in FileDownload in QSAN Storage Manager allows remote authenticated attackers download arbitrary files via the Url path parameter. | 4.0 |
2021-07-07 | CVE-2021-32508 | Link Following vulnerability in Qsan Storage Manager Absolute Path Traversal vulnerability in FileStreaming in QSAN Storage Manager allows remote authenticated attackers access arbitrary files by injecting the Symbolic Link following the Url path parameter. | 4.0 |
2021-07-07 | CVE-2021-32509 | Link Following vulnerability in Qsan Storage Manager Absolute Path Traversal vulnerability in FileviewDoc in QSAN Storage Manager allows remote authenticated attackers access arbitrary files by injecting the Symbolic Link following the Url path parameter. | 4.0 |
2021-07-07 | CVE-2021-32510 | Information Exposure Through Directory Listing vulnerability in Qsan Storage Manager QSAN Storage Manager through directory listing vulnerability in antivirus function allows remote authenticated attackers to list arbitrary directories by injecting file path parameter. | 4.0 |
2021-07-07 | CVE-2021-32511 | Information Exposure Through Directory Listing vulnerability in Qsan Storage Manager QSAN Storage Manager through directory listing vulnerability in ViewBroserList allows remote authenticated attackers to list arbitrary directories via the file path parameter. | 4.0 |
2021-07-07 | CVE-2021-32512 | OS Command Injection vulnerability in Qsan Storage Manager QuickInstall in QSAN Storage Manager does not filter special parameters properly that allows remote unauthenticated attackers to inject and execute arbitrary commands. | 7.5 |
2021-07-07 | CVE-2021-32513 | OS Command Injection vulnerability in Qsan Storage Manager QsanTorture in QSAN Storage Manager does not filter special parameters properly that allows remote unauthenticated attackers to inject and execute arbitrary commands. | 7.5 |
2021-07-07 | CVE-2021-32514 | Unspecified vulnerability in Qsan Storage Manager Improper access control vulnerability in FirmwareUpgrade in QSAN Storage Manager allows remote attackers to reboot and discontinue the device. | 5.0 |
2021-07-07 | CVE-2021-32515 | Information Exposure Through Directory Listing vulnerability in Qsan Storage Manager Directory listing vulnerability in share_link in QSAN Storage Manager allows attackers to list arbitrary directories and further access credential information. | 5.0 |