peter bassill · operator
$ cve CVE-2013-3631 JSON

CVE-2013-3631 EXPLOIT

6.0
MEDIUM · CVSS 2.0 · EPSS 13.7% (pctl 96)

Patch early

A public exploit exists.

Description

NAS4Free 9.1.0.1.804 and earlier allows remote authenticated users to execute arbitrary PHP code via a request to exec.php, aka the "Advanced | Execute Command" feature. NOTE: this issue might not be a vulnerability, since it appears to be part of legitimate, intentionally-exposed functionality by the developer and is allowed within the intended security policy.

Scoring

CVSS6.0 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:S/C:P/I:P/A:P
EPSS13.73% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-94
On CISA KEVno
Public exploityes
Published2013-11-02
Last modified2026-06-16

Affected (1)

VendorProduct
nas4freenas4free

Public exploits

SourceTitleDate
exploit-dbNAS4Free - Remote Code Execution (Metasploit)2013-10-31

References

→ the Explorer  ·  watch your stack  ·  NVD