handle_daylightsaving.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.0.0 through 3.0.0, NUUO Crystal 2.2.1 through 3.2.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attackers to execute arbitrary PHP code via the NTPServer parameter.
                
            References
                    | Link | Resource | 
|---|---|
| http://www.kb.cert.org/vuls/id/856152 | Third Party Advisory US Government Resource | 
| http://www.securityfocus.com/bid/92318 | |
| https://www.exploit-db.com/exploits/40200/ | |
| http://www.kb.cert.org/vuls/id/856152 | Third Party Advisory US Government Resource | 
| http://www.securityfocus.com/bid/92318 | |
| https://www.exploit-db.com/exploits/40200/ | 
Configurations
                    Configuration 1 (hide)
| 
 | 
Configuration 2 (hide)
| 
 | 
Configuration 3 (hide)
| 
 | 
Configuration 4 (hide)
| 
 | 
History
                    No history.
Information
                Published : 2016-08-31 15:59
Updated : 2025-04-12 10:46
NVD link : CVE-2016-5675
Mitre link : CVE-2016-5675
CVE.ORG link : CVE-2016-5675
JSON object : View
Products Affected
                nuuo
- nvrsolo
- nvrmini_2
- crystal
netgear
- readynas_surveillance
CWE
                
                    
                        
                        CWE-20
                        
            Improper Input Validation
