CVE-2013-3631: NAS4FREE
Medium severity, CVSS 6.0. EPSS: 13.7% chance of exploitation in the next 30 days.
NAS4Free 9.1.0.1.804 and earlier allows remote authenticated users to execute arbitrary PHP code via a request to exec.php, aka the "Advanced | Execute Command" feature. NOTE: this issue might not be a vulnerability, since it appears to be part of legitimate, intentionally-exposed functionality by the developer and is allowed within the intended security policy.
Affected products
- NAS4FREE NAS4FREE: up to and including 9.1.0.1.804; version 9.1.0.1.798 only
Published 2013-11-02. Last modified 2026-06-16.