First published: Mon Jun 09 2014(Updated: )
QNAP Photo Station before firmware 4.0.3 build0912 allows remote attackers to list OS user accounts via a request to photo/p/api/list.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
QNAP Photo Station Firmware | <=4.0.3 | |
QNAP Photo Station Firmware | ||
All of | ||
QNAP Photo Station Firmware | <=4.0.3 | |
QNAP Photo Station Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-5760 has been classified as a medium severity vulnerability due to the potential for unauthorized access to OS user accounts.
To fix CVE-2013-5760, update your QNAP Photo Station firmware to version 4.0.3 build0912 or later.
CVE-2013-5760 affects QNAP Photo Station versions prior to firmware 4.0.3 build0912.
Yes, CVE-2013-5760 can be exploited remotely by attackers to list OS user accounts.
No, authentication is not required to exploit CVE-2013-5760, making it particularly concerning for users.