First published: Sat Feb 27 2016(Updated: )
QNAP Signage Station before 2.0.1 allows remote attackers to bypass authentication, and consequently upload files, via a spoofed HTTP request.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
QNAP Signage Station | =2.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-6036 is classified as a high severity vulnerability due to its potential for remote exploitation.
To fix CVE-2015-6036, upgrade QNAP Signage Station to version 2.0.1 or later.
CVE-2015-6036 is an authentication bypass vulnerability that allows unauthorized file uploads.
CVE-2015-6036 affects QNAP Signage Station version 2.0.0 and earlier.
Yes, CVE-2015-6036 can be exploited remotely by attackers through spoofed HTTP requests.