Loading
Seagate BlackArmor NAS allows remote attackers to execute arbitrary code via the session parameter to localhost/backupmgt/localJob.php or the auth_name parameter to localhost/backupmgmt/pre_connect_check.php.
Use CWE-20, Seagate vendor hub and Blackarmor Nas 220 Firmware product page to widen CVE-2014-3206 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2014-3205, CVE-2013-6924 and CVE-2013-6922 for nearby disclosures in the same product family.