
CVE-2015-9105
https://notcve.org/view.php?id=CVE-2015-9105
30 Jun 2017 — Multiple cross-site scripting (XSS) vulnerabilities in Synology Video Station 1.2 before 1.2-0455, 1.5 before 1.5-0772, and 1.6 before 1.6-0847 allow remote authenticated attackers to inject arbitrary web script or HTML via the (1) file name or (2) collection name of videos. Varias vulnerabilidades de XSS (cross-site scripting) en Synology Video Station versión 1.2 y anteriores a la 1.2-0455, versión 1.5 y anteriores a la 1.5-0772 y versión 1.6 y anteriores a la 1.6-0847, permiten a atacantes remotos autent... • http://www.fortiguard.com/zeroday/FG-VD-15-107 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2015-6910
https://notcve.org/view.php?id=CVE-2015-6910
11 Sep 2015 — SQL injection vulnerability in Synology Video Station before 1.5-0757 allows remote attackers to execute arbitrary SQL commands via the id parameter to audiotrack.cgi. Vulnerabilidad de inyección SQL en Synology Video Station en versiones anteriores a 1.5-0757, permite a atacantes remotos ejecutar comandos SQL arbitrarios a través del parámetro id en audiotrack.cgi. • http://packetstormsecurity.com/files/133519/Synology-Video-Station-1.5-0757-Command-Injection-SQL-Injection.html • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2015-6911 – Synology Video Station 1.5-0757 - Multiple Vulnerabilities
https://notcve.org/view.php?id=CVE-2015-6911
11 Sep 2015 — SQL injection vulnerability in Synology Video Station before 1.5-0763 allows remote attackers to execute arbitrary SQL commands via the id parameter to watchstatus.cgi. Vulnerabilidad de inyección SQL en Synology Video Station en versiones anteriores a 1.5-0763, permite a atacantes remotos ejecutar comandos SQL arbitrarios a través del parámetro id en watchstatus.cgi. • https://www.exploit-db.com/exploits/38128 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2015-6912 – Synology Video Station 1.5-0757 - Multiple Vulnerabilities
https://notcve.org/view.php?id=CVE-2015-6912
11 Sep 2015 — Synology Video Station before 1.5-0763 allows remote attackers to execute arbitrary shell commands via shell metacharacters in the subtitle_codepage parameter to subtitle.cgi. Vulnerabilidad en Synology Video Station en versiones anteriores a 1.5-0763, permite a atacantes remotos ejecutar comandos shell arbitrarios a través de metacaracteres de la shell en el parámetro subtitle_codepage en subtitle.cgi. • https://www.exploit-db.com/exploits/38128 • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •