cve/2016/CVE-2016-5675.md

21 lines
859 B
Markdown
Raw Normal View History

2024-05-26 14:27:05 +02:00
### [CVE-2016-5675](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5675)
![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen)
### Description
handle_daylightsaving.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.0.0 through 3.0.0, NUUO Crystal 2.2.1 through 3.2.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attackers to execute arbitrary PHP code via the NTPServer parameter.
### POC
#### Reference
- http://www.kb.cert.org/vuls/id/856152
2024-06-09 00:33:16 +00:00
- http://www.kb.cert.org/vuls/id/856152
2024-05-26 14:27:05 +02:00
- https://www.exploit-db.com/exploits/40200/
2024-06-09 00:33:16 +00:00
- https://www.exploit-db.com/exploits/40200/
2024-05-26 14:27:05 +02:00
#### Github
No PoCs found on GitHub currently.