QNAP Turbo NAS Multiple Security Vulnerabilities
BID:54069
Info
QNAP Turbo NAS Multiple Security Vulnerabilities
| Bugtraq ID: | 54069 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 13 2012 12:00AM |
| Updated: | Jun 13 2012 12:00AM |
| Credit: | Nadeem Salim and Phil Taylor of Sense of Security Labs |
| Vulnerable: |
Qnap Turbo NAS 0 |
| Not Vulnerable: | |
Discussion
QNAP Turbo NAS Multiple Security Vulnerabilities
QNAP Turbo NAS is prone to the following security vulnerabilities:
1. Multiple code-injection vulnerabilities.
2. An Information Disclosure Weakness.
3. Multiple unspecified cross-site scripting vulnerabilities.
An attacker may leverage these issues to steal cookie-based authentication credentials, compromise the application, access or modify data, exploit latent vulnerabilities in the underlying database, execute arbitrary commands in the context of the application, disclose sensitive information, perform certain administrative actions, or gain unauthorized access.
QNAP Turbo NAS running firmware 3.6.1 Build 0302T and prior are vulnerable.
QNAP Turbo NAS is prone to the following security vulnerabilities:
1. Multiple code-injection vulnerabilities.
2. An Information Disclosure Weakness.
3. Multiple unspecified cross-site scripting vulnerabilities.
An attacker may leverage these issues to steal cookie-based authentication credentials, compromise the application, access or modify data, exploit latent vulnerabilities in the underlying database, execute arbitrary commands in the context of the application, disclose sensitive information, perform certain administrative actions, or gain unauthorized access.
QNAP Turbo NAS running firmware 3.6.1 Build 0302T and prior are vulnerable.
Exploit / POC
QNAP Turbo NAS Multiple Security Vulnerabilities
An attacker can use a web browser to exploit some of these issues.
To exploit a cross-site scripting, an attacker must entice an unsuspecting user to follow a malicious URI.
The following example URI is available:
http://www.example.com/cgi-bin/Qdownload/DS_RSS_Option.cgi?_dc=1331164660690&url=http%3A%2F%2Fexample.com&title=test&keyword=`touch%20%2ftesto%2etxt`&todo=add&sid=i9nonapr&ver=2.0
An attacker can use a web browser to exploit some of these issues.
To exploit a cross-site scripting, an attacker must entice an unsuspecting user to follow a malicious URI.
The following example URI is available:
http://www.example.com/cgi-bin/Qdownload/DS_RSS_Option.cgi?_dc=1331164660690&url=http%3A%2F%2Fexample.com&title=test&keyword=`touch%20%2ftesto%2etxt`&todo=add&sid=i9nonapr&ver=2.0
Solution / Fix
QNAP Turbo NAS Multiple Security Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
QNAP Turbo NAS Multiple Security Vulnerabilities
References:
References:
- QNAP Storage Products Homepage (QNAP Systems)
- SOS-12-006: QNAP Turbo NAS �?? Multiple Vulnerabilities (Sense of Security Labs)