Show filters
60 Total Results
Displaying 11-20 of 60
Sort by:
Attacker Value
Unknown

CVE-2021-44057

Disclosure Date: May 06, 2022 (last updated October 07, 2023)
An improper authentication vulnerability has been reported to affect QNAP device running Photo Station. If exploited, this vulnerability allows attackers to compromise the security of the system. We have already fixed this vulnerability in the following versions of Photo Station: Photo Station 6.0.20 ( 2022/02/15 ) and later Photo Station 5.7.16 ( 2022/02/11 ) and later Photo Station 5.4.13 ( 2022/02/11 ) and later
Attacker Value
Unknown

CVE-2021-34356

Disclosure Date: October 01, 2021 (last updated February 23, 2025)
A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Photo Station. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Photo Station: Photo Station 6.0.18 ( 2021/09/01 ) and later
Attacker Value
Unknown

CVE-2021-34355

Disclosure Date: October 01, 2021 (last updated February 23, 2025)
A cross-site scripting (XSS) vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Photo Station: Photo Station 5.4.10 ( 2021/08/19 ) and later Photo Station 5.7.13 ( 2021/08/19 ) and later Photo Station 6.0.18 ( 2021/09/01 ) and later
Attacker Value
Unknown

CVE-2021-34354

Disclosure Date: October 01, 2021 (last updated February 23, 2025)
A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Photo Station. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Photo Station: Photo Station 6.0.18 ( 2021/09/01 ) and later
Attacker Value
Unknown

CVE-2021-29089

Disclosure Date: June 02, 2021 (last updated February 22, 2025)
Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in thumbnail component in Synology Photo Station before 6.8.14-3500 allows remote attackers users to execute arbitrary SQL commands via unspecified vectors.
Attacker Value
Unknown

CVE-2021-29090

Disclosure Date: June 01, 2021 (last updated February 22, 2025)
Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in PHP component in Synology Photo Station before 6.8.14-3500 allows remote authenticated users to execute arbitrary SQL command via unspecified vectors.
Attacker Value
Unknown

CVE-2021-29091

Disclosure Date: June 01, 2021 (last updated February 22, 2025)
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in file management component in Synology Photo Station before 6.8.14-3500 allows remote authenticated users to write arbitrary files via unspecified vectors.
Attacker Value
Unknown

CVE-2021-29092

Disclosure Date: May 31, 2021 (last updated February 22, 2025)
Unrestricted upload of file with dangerous type vulnerability in file management component in Synology Photo Station before 6.8.14-3500 allows remote authenticated users to execute arbitrary code via unspecified vectors.
Attacker Value
Unknown

CVE-2020-2502

Disclosure Date: February 17, 2021 (last updated February 22, 2025)
This cross-site scripting vulnerability in Photo Station allows remote attackers to inject malicious code. QANP We have already fixed this vulnerability in the following versions of Photo Station. Photo Station 6.0.11 and later
Attacker Value
Unknown

CVE-2020-2491

Disclosure Date: December 07, 2020 (last updated February 22, 2025)
This cross-site scripting vulnerability in Photo Station allows remote attackers to inject malicious code. QANP We have already fixed this vulnerability in the following versions of Photo Station. QTS 4.5.1: Photo Station 6.0.12 and later QTS 4.4.3: Photo Station 6.0.12 and later QTS 4.3.6: Photo Station 5.7.12 and later QTS 4.3.4: Photo Station 5.7.13 and later QTS 4.3.3: Photo Station 5.4.10 and later QTS 4.2.6: Photo Station 5.2.11 and later