CVE-2016-10329
https://notcve.org/view.php?id=CVE-2016-10329
Command injection vulnerability in login.php in Synology Photo Station before 6.5.3-3226 allows remote attackers to execute arbitrary code via shell metacharacters in the crafted 'X-Forwarded-For' header. Vulnerabilidad de inyección de comandos en login.php en Synology Photo Station en versiones anteriores a la 6.5.3-3226, que permitiría a atacantes remotos ejecutar código arbitrario a través metacaracteres de shell en una cabecera 'X-Forwarded-For' manipulada. • http://seclists.org/oss-sec/2016/q1/236 https://bamboofox.github.io/2017/03/20/Synology-Bug-Bounty-2016/#Vul-01-PhotoStation-Login-without-password https://bamboofox.github.io/2017/03/20/Synology-Bug-Bounty-2016/#Vul-02-PhotoStation-Remote-Code-Execution https://www.synology.com/en-global/support/security/Photo_Station_6_5_3_3226 • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •
CVE-2016-10323
https://notcve.org/view.php?id=CVE-2016-10323
Synology Photo Station before 6.3-2958 allows local users to gain privileges by leveraging setuid execution of a "synophoto_dsm_user --copy-no-ea" command. Synology Photo Station en versiones anteriores a 6.3-2958 permite a los usuarios locales obtener privilegios aprovechando la ejecución de setuid de un comando "synophoto_dsm_user --copy-no-ea". • http://seclists.org/oss-sec/2016/q1/236 https://www.synology.com/en-us/releaseNote/PhotoStation • CWE-264: Permissions, Privileges, and Access Controls •
CVE-2016-10322
https://notcve.org/view.php?id=CVE-2016-10322
Synology Photo Station before 6.3-2958 allows remote authenticated guest users to execute arbitrary commands via shell metacharacters in the X-Forwarded-For HTTP header to photo/login.php. Synology Photo Station en versiones anteriores a 6.3-2958 permite a los usuarios invitados autenticados remotos ejecutar comandos arbitrarios a través de metacaracteres de shell en el encabezado HTTP X-Forwarded-For a photo/login.php. • http://seclists.org/oss-sec/2016/q1/236 https://www.synology.com/en-us/releaseNote/PhotoStation • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •
CVE-2015-6910
https://notcve.org/view.php?id=CVE-2015-6910
SQL injection vulnerability in Synology Video Station before 1.5-0757 allows remote attackers to execute arbitrary SQL commands via the id parameter to audiotrack.cgi. Vulnerabilidad de inyección SQL en Synology Video Station en versiones anteriores a 1.5-0757, permite a atacantes remotos ejecutar comandos SQL arbitrarios a través del parámetro id en audiotrack.cgi. • http://packetstormsecurity.com/files/133519/Synology-Video-Station-1.5-0757-Command-Injection-SQL-Injection.html http://seclists.org/fulldisclosure/2015/Sep/31 http://www.securityfocus.com/archive/1/536427/100/0/threaded https://www.securify.nl/advisory/SFY20150810/synology_video_station_command_injection_and_multiple_sql_injection_vulnerabilities.html https://www.synology.com/en-global/releaseNote/VideoStation?model=DS715 https://www.synology.com/en-global/support/security/Video_Station_1_5_0757 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2015-6909
https://notcve.org/view.php?id=CVE-2015-6909
Cross-site scripting (XSS) vulnerability in the "Create download task via file upload" feature in Synology Download Station before 3.5-2962 allows remote attackers to inject arbitrary web script or HTML via the name element in the Info dictionary in a torrent file. Vulnerabilidad de XSS en la funcionalidad 'Create download task via file upload' en Synology Download Station en versiones anteriores a 3.5-2962, permite a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a través del nombre del elemento en el diccionario Info en un archivo torrent. • http://packetstormsecurity.com/files/133520/Synology-Download-Station-3.5-2956-3.5-2962-Cross-Site-Scripting.html http://seclists.org/fulldisclosure/2015/Sep/32 http://www.securityfocus.com/archive/1/536428/100/0/threaded https://www.securify.nl/advisory/SFY20150809/multiple_cross_site_scripting_vulnerabilities_in_synology_download_station.html https://www.synology.com/en-global/releaseNote/DownloadStation?model=DS715 https://www.synology.com/en-global/support/security/Download_Station_3_5_2962 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •