First published: Sat Feb 27 2016(Updated: )
Unrestricted file upload vulnerability in QNAP Signage Station before 2.0.1 allows remote authenticated users to execute arbitrary code by uploading an executable file, and then accessing this file via an unspecified URL.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
QNAP Signage Station | <=2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-6022 has a medium severity level due to its ability to allow remote code execution.
To fix CVE-2015-6022, upgrade QNAP Signage Station to version 2.0.1 or later.
CVE-2015-6022 affects QNAP Signage Station versions prior to 2.0.1.
CVE-2015-6022 can be exploited by remote authenticated users with the ability to upload files.
CVE-2015-6022 facilitates arbitrary code execution through unrestricted file uploads.