CVE-2013-5760: Infoleak
Published Jun 9, 2014
·Updated
QNAP Photo Station before firmware 4.0.3 build0912 allows remote attackers to list OS user accounts via a request to photo/p/api/list.php.
Affected Software
4 affected components
QNAP Photo Station Firmware<=4.0.3
QNAP Photo Station
All of the following
QNAP Photo Station Firmware<=4.0.3
QNAP Photo Station
Event History
Jun 9, 2014
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Data Sourced
via NVD·07:55 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2013-5760?
CVE-2013-5760 has been classified as a medium severity vulnerability due to the potential for unauthorized access to OS user accounts.
2
How do I fix CVE-2013-5760?
To fix CVE-2013-5760, update your QNAP Photo Station firmware to version 4.0.3 build0912 or later.
3
What systems are affected by CVE-2013-5760?
CVE-2013-5760 affects QNAP Photo Station versions prior to firmware 4.0.3 build0912.
4
Can CVE-2013-5760 be exploited remotely?
Yes, CVE-2013-5760 can be exploited remotely by attackers to list OS user accounts.
5
Is authentication required to exploit CVE-2013-5760?
No, authentication is not required to exploit CVE-2013-5760, making it particularly concerning for users.