4.3
CVSSv2

CVE-2013-6923

Published: 09/01/2014 Updated: 29/08/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in Seagate BlackArmor NAS 220 devices with firmware sg2000-2000.1331 allow remote malicious users to inject arbitrary web script or HTML via the (1) fullname parameter to admin/access_control_user_edit.php or (2) workname parameter to admin/network_workgroup_domain.php.

Vulnerable Product Search on Vulmon Subscribe to Product

seagate blackarmor nas 220 firmware sg2000-2000.1331

seagate blackarmor nas 220 st320005lsa10g-rk

seagate blackarmor nas 220 st340005lsa10g-rk

seagate blackarmor nas 220 stav6000100

Exploits

# Exploit Title: Seagate BlackArmor NAS - Multiple Persistent Cross Site Scripting Vulnerabilities # Google Dork: N/A # Date: 04-01-2014 # Exploit Author: Jeroen - IT Nerdbox # Vendor Homepage: <wwwseagatecom/> wwwseagatecom/ # Software Link: <wwwseagatecom/support/downloads/item/banas-220-firmware-master-d ...
Seagate BlackArmor NAS sg2000-20001331 suffers from multiple persistent cross site scripting vulnerabilities ...