First published: Wed Aug 31 2016(Updated: )
handle_daylightsaving.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.0.0 through 3.0.0, NUUO Crystal 2.2.1 through 3.2.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attackers to execute arbitrary PHP code via the NTPServer parameter.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
NETGEAR ReadyNAS Surveillance | =1.1.1 | |
NETGEAR ReadyNAS Surveillance | =1.1.2 | |
NETGEAR ReadyNAS Surveillance | =1.2.0.4 | |
NETGEAR ReadyNAS Surveillance | =1.3.2.4 | |
NETGEAR ReadyNAS Surveillance | =1.3.2.14 | |
NETGEAR ReadyNAS Surveillance | =1.4.0 | |
NETGEAR ReadyNAS Surveillance | =1.4.1 | |
NETGEAR ReadyNAS Surveillance | =1.4.2 | |
NUUO Crystal | =2.2.1 | |
NUUO Crystal | =3.0.0 | |
NUUO Crystal | =3.1.0 | |
NUUO Crystal | =3.2.0 | |
NUUO NVRsolo | =1.0.0 | |
NUUO NVRsolo | =1.0.1 | |
NUUO NVRsolo | =1.1.0 | |
NUUO NVRsolo | =1.1.0.117 | |
NUUO NVRsolo | =1.1.1 | |
NUUO NVRsolo | =1.1.2 | |
NUUO NVRsolo | =1.2.0 | |
NUUO NVRsolo | =1.3.0 | |
NUUO NVRsolo | =1.75 | |
NUUO NVRsolo | =2.0.0 | |
NUUO NVRsolo | =2.0.1 | |
NUUO NVRsolo | =2.1.5 | |
NUUO NVRsolo | =2.2.2 | |
NUUO NVRsolo | =2.3 | |
NUUO NVRsolo | =2.3.1.20 | |
NUUO NVRsolo | =2.3.7.9 | |
NUUO NVRsolo | =2.3.7.10 | |
NUUO NVRsolo | =2.3.9.6 | |
NUUO NVRsolo | =3.0.0 | |
NUUO NVRmini 2 | =1.7.5 | |
NUUO NVRmini 2 | =1.7.6 | |
NUUO NVRmini 2 | =2.0.0 | |
NUUO NVRmini 2 | =2.2.1 | |
NUUO NVRmini 2 | =3.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.