Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Pasquale Fiorillo

Researcher fromISGroup
#26626of 53,633
9.6Total CVSS
Vulnerabilities · 2
Low
1
High
1
PT-2017-16402
7.5
2017-03-23
Qnap · Qts · CVE-2017-5227
**Name of the Vulnerable Software and Affected Versions** QNAP QTS versions prior to 4.2.4 Build 20170313 **Description** The issue allows local users to obtain sensitive Domain Administrator password information by reading data in an XOR format within the /etc/config/uLinux.conf configuration file. **Recommendations** For versions prior to 4.2.4 Build 20170313, update to version 4.2.4 Build 20170313 or later to resolve the issue.
PT-2015-7061
2.1
2015-10-16
Veeam · Veeam Backup & Replication · CVE-2015-5742
**Name of the Vulnerable Software and Affected Versions** Veeam Backup & Replication versions prior to 8.0 update 3 **Description** The issue allows local users to obtain sensitive information by reading log files with world-readable permissions, where local administrator credentials are stored. This is due to the storage of credentials in log files by VeeamVixProxy. **Recommendations** For versions prior to 8.0 update 3, update to version 8.0 update 3 or later to resolve the issue. As a temporary workaround, consider restricting access to the log files to minimize the risk of exploitation.