Vulnerability Description
QNAP Photo Station before firmware 4.0.3 build0912 allows remote attackers to list OS user accounts via a request to photo/p/api/list.php.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Qnap | Photo Station Firmware | <= 4.0.3 |
| Qnap | Photo Station | - |
Related Weaknesses (CWE)
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/89117
- https://www3.trustwave.com/spiderlabs/advisories/TWSL2013-029.txtExploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/89117
- https://www3.trustwave.com/spiderlabs/advisories/TWSL2013-029.txtExploit
FAQ
What is CVE-2013-5760?
CVE-2013-5760 is a vulnerability with a CVSS score of 5.0 (MEDIUM). QNAP Photo Station before firmware 4.0.3 build0912 allows remote attackers to list OS user accounts via a request to photo/p/api/list.php.
How severe is CVE-2013-5760?
CVE-2013-5760 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-5760?
Check the references section above for vendor advisories and patch information. Affected products include: Qnap Photo Station Firmware, Qnap Photo Station.