漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
QTS, QuTS hero
Vulnerability Description
A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QTS 5.2.9.3492 build 20260507 and later QuTS hero h5.2.9.3499 build 20260514 and later
CVSS Information
N/A
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Vulnerability Title
QNAP Systems QTS和QNAP Systems QuTS hero 操作系统命令注入漏洞
Vulnerability Description
QNAP Systems QTS和QNAP Systems QuTS hero都是中国台湾威联通科技(QNAP Systems)公司的一个具有数据存储与管理功能的软件。 QNAP Systems QTS和QNAP Systems QuTS hero存在操作系统命令注入漏洞,该漏洞源于命令注入,可能导致远程攻击者在获取管理员账户后执行任意命令。以下产品及版本受到影响:QTS 5.2.9.3492之前版本和QuTS hero h5.2.9.3499之前版本。
CVSS Information
N/A
Vulnerability Type
N/A