handle_daylightsaving.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.0.0 through 3.0.0, NUUO Crystal 2.2.1 through 3.2.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attackers to execute arbitrary PHP code via the NTPServer parameter.
References
Link | Resource |
---|---|
http://www.kb.cert.org/vuls/id/856152 | Third Party Advisory US Government Resource |
http://www.securityfocus.com/bid/92318 | |
https://www.exploit-db.com/exploits/40200/ |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Information
Published : 2016-08-31 08:59
Updated : 2017-09-02 18:29
NVD link : CVE-2016-5675
Mitre link : CVE-2016-5675
JSON object : View
CWE
CWE-20
Improper Input Validation
Products Affected
nuuo
- crystal
- nvrmini_2
- nvrsolo
netgear
- readynas_surveillance