Show filters
60 Total Results
Displaying 51-60 of 60
Sort by:
Attacker Value
Unknown

CVE-2015-9102

Disclosure Date: June 30, 2017 (last updated November 26, 2024)
Multiple cross-site scripting (XSS) vulnerabilities in Synology Photo Station 6.0 before 6.0-2638 and 6.3 before 6.3-2962 allow remote authenticated attackers to inject arbitrary web script or HTML via the (1) album name, (2) file name of uploaded photos, (3) description of photos, or (4) tag of the photos.
0
Attacker Value
Unknown

CVE-2017-9552

Disclosure Date: June 13, 2017 (last updated November 26, 2024)
A design flaw in authentication in Synology Photo Station 6.0-2528 through 6.7.1-3419 allows local users to obtain credentials via cmdline. Synology Photo Station employs the synophoto_dsm_user program to authenticate username and password by "synophoto_dsm_user --auth USERNAME PASSWORD", and local users are able to obtain credentials by sniffing "/proc/*/cmdline".
0
Attacker Value
Unknown

CVE-2016-10330

Disclosure Date: May 12, 2017 (last updated November 08, 2023)
Directory traversal vulnerability in synophoto_dsm_user, a SUID program, as used in Synology Photo Station before 6.5.3-3226 allows local users to write to arbitrary files via unspecified vectors.
0
Attacker Value
Unknown

CVE-2016-10329

Disclosure Date: May 12, 2017 (last updated November 26, 2024)
Command injection vulnerability in login.php in Synology Photo Station before 6.5.3-3226 allows remote attackers to execute arbitrary code via shell metacharacters in the crafted 'X-Forwarded-For' header.
0
Attacker Value
Unknown

CVE-2016-10331

Disclosure Date: May 12, 2017 (last updated November 26, 2024)
Directory traversal vulnerability in download.php in Synology Photo Station before 6.5.3-3226 allows remote attackers to read arbitrary files via a full pathname in the id parameter.
0
Attacker Value
Unknown

CVE-2016-10323

Disclosure Date: April 10, 2017 (last updated November 26, 2024)
Synology Photo Station before 6.3-2958 allows local users to gain privileges by leveraging setuid execution of a "synophoto_dsm_user --copy-no-ea" command.
0
Attacker Value
Unknown

CVE-2016-10322

Disclosure Date: April 10, 2017 (last updated November 26, 2024)
Synology Photo Station before 6.3-2958 allows remote authenticated guest users to execute arbitrary commands via shell metacharacters in the X-Forwarded-For HTTP header to photo/login.php.
0
Attacker Value
Unknown

CVE-2015-4656

Disclosure Date: June 18, 2015 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Synology Photo Station before 6.3-2945 allow remote attackers to inject arbitrary web script or HTML via the (1) success parameter to login.php or (2) crafted URL parameters to index.php, as demonstrated by the t parameter to photo/.
0
Attacker Value
Unknown

CVE-2012-1556

Disclosure Date: September 12, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in Synology Photo Station 5 for DiskStation Manager (DSM) 3.2-1955 allows remote attackers to inject arbitrary web script or HTML via the name parameter to photo/photo_one.php.
0
Attacker Value
Unknown

CVE-2013-5760

Disclosure Date: June 09, 2014 (last updated October 05, 2023)
QNAP Photo Station before firmware 4.0.3 build0912 allows remote attackers to list OS user accounts via a request to photo/p/api/list.php.
0