PT-2014-3218 · Seagate · Seagate Blackarmor Nas 220

Jeroen

·

Published

2014-01-09

·

Updated

2017-08-29

·

CVE-2013-6923

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Seagate BlackArmor NAS 220 version sg2000-2000.1331
Description The issue concerns multiple cross-site scripting (XSS) vulnerabilities. These vulnerabilities allow remote attackers to inject arbitrary web script or HTML. Specifically, the fullname parameter to "admin/access control user edit.php" and the workname parameter to "admin/network workgroup domain.php" are vulnerable.
Recommendations For version sg2000-2000.1331, avoid using the fullname parameter in the "admin/access control user edit.php" and the workname parameter in the "admin/network workgroup domain.php" until the issue is resolved. As a temporary workaround, consider restricting access to these parameters to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-6923

Affected Products

Seagate Blackarmor Nas 220