vendor:
IB-NAS5220 / IB-NAS4220-B
by:
Michael Messner
8,8
CVSS
HIGH
Authentication Bypass, Stored XSS and Unauthenticated OS Command Injection
79
CWE
Product Name: IB-NAS5220 / IB-NAS4220-B
Affected Version From: IB5220: 2.6.3-20100206S, IB4220: 2.6.3.IB.1.RS.1
Affected Version To: IB5220: 2.6.3-20100206S, IB4220: 2.6.3.IB.1.RS.1
Patch Exists: NO
Related CWE: N/A
CPE: IB-NAS5220, IB-NAS4220-B
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2010
Authentication Bypass, Stored XSS and Unauthenticated OS Command Injection in Raidsonic IB-NAS5220 / IB-NAS4220-B
Accessing the URL http://<IP>/nav.cgi?foldName=adm&localePreference=en allows an attacker to bypass the login procedure. System -> Time Settings -> NTP Server -> User Define allows an attacker to inject scripts into the parameter ntp_name without authentication. The vulnerability is caused by missing input validation in the ping_size parameter and can be exploited to inject and execute arbitrary shell commands.
Mitigation:
No known solution available.