Vulnerabilities
Vulnerable Software
Asustor:  >> Data Master  >> 2.1  Security Vulnerabilities
ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to upload files to arbitrary locations due to a path traversal vulnerability. This could lead to code execution if the "Web Server" feature is enabled.
CVSS Score
7.5
EPSS Score
0.028
Published
2018-08-27
ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to delete any file on the file system due to a path traversal vulnerability in wallpaper.cgi.
CVSS Score
6.5
EPSS Score
0.006
Published
2018-08-27
ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to enumerate all user accounts via user.cgi.
CVSS Score
4.3
EPSS Score
0.004
Published
2018-08-27
ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to read any file on a share by providing the full path. For example, /home/admin/.ash_history.
CVSS Score
6.5
EPSS Score
0.006
Published
2018-08-27
ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to read any file on the file system when providing the full path to loginimage.cgi.
CVSS Score
6.5
EPSS Score
0.01
Published
2018-08-27
ASUSTOR Data Master 3.1.5 and below makes an HTTP request for a configuration file that is vulnerable to XSS. A man in the middle can take advantage of this by inserting Javascript into the configuration files Version field.
CVSS Score
6.1
EPSS Score
0.002
Published
2018-08-27


Contact Us

Shodan ® - All rights reserved