Turbo NAS Firmware utilRequest.cgi Directory Traversal Vulnerabilities
Description
Andrea Fabrizi has reported some vulnerabilities in Turbo NAS Firmware, which can be exploited by malicious users to disclose sensitive data and manipulate certain data.
Input passed via the "source_file" parameter to cgi-bin/filemanager/utilRequest.cgi (when "func" is not set or set to "delete", "copy", "move", or "get_acl_properties") is not properly verified before being used. This can be exploited to disclose, delete, move, or copy arbitrary files via directory traversal sequences.
The vulnerabilities are reported in versions 3.7.3 build 20120801 and prior running on QNAP TS-1279U-RP.