Show filters
300 Total Results
Displaying 271-280 of 300
Sort by:
Attacker Value
Unknown
CVE-2017-11152
Disclosure Date: August 08, 2017 (last updated November 26, 2024)
Directory traversal vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to write arbitrary files via the path parameter.
0
Attacker Value
Unknown
CVE-2017-9553
Disclosure Date: July 24, 2017 (last updated January 15, 2025)
A design flaw in SYNO.API.Encryption in Synology DiskStation Manager (DSM) before 6.1.3-15152 allows remote attackers to bypass the encryption protection mechanism via the crafted version parameter.
0
Attacker Value
Unknown
CVE-2015-9103
Disclosure Date: June 30, 2017 (last updated November 26, 2024)
Multiple cross-site scripting (XSS) vulnerabilities in Synology Note Station 1.1-0212 and earlier allow remote authenticated attackers to inject arbitrary web script or HTML via the (1) note title or (2) file name of attachments.
0
Attacker Value
Unknown
CVE-2015-9105
Disclosure Date: June 30, 2017 (last updated November 26, 2024)
Multiple cross-site scripting (XSS) vulnerabilities in Synology Video Station 1.2 before 1.2-0455, 1.5 before 1.5-0772, and 1.6 before 1.6-0847 allow remote authenticated attackers to inject arbitrary web script or HTML via the (1) file name or (2) collection name of videos.
0
Attacker Value
Unknown
CVE-2015-9102
Disclosure Date: June 30, 2017 (last updated November 26, 2024)
Multiple cross-site scripting (XSS) vulnerabilities in Synology Photo Station 6.0 before 6.0-2638 and 6.3 before 6.3-2962 allow remote authenticated attackers to inject arbitrary web script or HTML via the (1) album name, (2) file name of uploaded photos, (3) description of photos, or (4) tag of the photos.
0
Attacker Value
Unknown
CVE-2015-9104
Disclosure Date: June 30, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerabilities in Synology Audio Station 5.1 before 5.1-2550 and 5.4 before 5.4-2857 allows remote authenticated attackers to inject arbitrary web script or HTML via the album title.
0
Attacker Value
Unknown
CVE-2017-9552
Disclosure Date: June 13, 2017 (last updated November 26, 2024)
A design flaw in authentication in Synology Photo Station 6.0-2528 through 6.7.1-3419 allows local users to obtain credentials via cmdline. Synology Photo Station employs the synophoto_dsm_user program to authenticate username and password by "synophoto_dsm_user --auth USERNAME PASSWORD", and local users are able to obtain credentials by sniffing "/proc/*/cmdline".
0
Attacker Value
Unknown
CVE-2016-10330
Disclosure Date: May 12, 2017 (last updated November 08, 2023)
Directory traversal vulnerability in synophoto_dsm_user, a SUID program, as used in Synology Photo Station before 6.5.3-3226 allows local users to write to arbitrary files via unspecified vectors.
0
Attacker Value
Unknown
CVE-2016-10329
Disclosure Date: May 12, 2017 (last updated November 26, 2024)
Command injection vulnerability in login.php in Synology Photo Station before 6.5.3-3226 allows remote attackers to execute arbitrary code via shell metacharacters in the crafted 'X-Forwarded-For' header.
0
Attacker Value
Unknown
CVE-2016-10331
Disclosure Date: May 12, 2017 (last updated November 26, 2024)
Directory traversal vulnerability in download.php in Synology Photo Station before 6.5.3-3226 allows remote attackers to read arbitrary files via a full pathname in the id parameter.
0