CVE-2016-10329
https://notcve.org/view.php?id=CVE-2016-10329
Command injection vulnerability in login.php in Synology Photo Station before 6.5.3-3226 allows remote attackers to execute arbitrary code via shell metacharacters in the crafted 'X-Forwarded-For' header. Vulnerabilidad de inyección de comandos en login.php en Synology Photo Station en versiones anteriores a la 6.5.3-3226, que permitiría a atacantes remotos ejecutar código arbitrario a través metacaracteres de shell en una cabecera 'X-Forwarded-For' manipulada. • http://seclists.org/oss-sec/2016/q1/236 https://bamboofox.github.io/2017/03/20/Synology-Bug-Bounty-2016/#Vul-01-PhotoStation-Login-without-password https://bamboofox.github.io/2017/03/20/Synology-Bug-Bounty-2016/#Vul-02-PhotoStation-Remote-Code-Execution https://www.synology.com/en-global/support/security/Photo_Station_6_5_3_3226 • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •
CVE-2016-10323
https://notcve.org/view.php?id=CVE-2016-10323
Synology Photo Station before 6.3-2958 allows local users to gain privileges by leveraging setuid execution of a "synophoto_dsm_user --copy-no-ea" command. Synology Photo Station en versiones anteriores a 6.3-2958 permite a los usuarios locales obtener privilegios aprovechando la ejecución de setuid de un comando "synophoto_dsm_user --copy-no-ea". • http://seclists.org/oss-sec/2016/q1/236 https://www.synology.com/en-us/releaseNote/PhotoStation • CWE-264: Permissions, Privileges, and Access Controls •
CVE-2016-10322
https://notcve.org/view.php?id=CVE-2016-10322
Synology Photo Station before 6.3-2958 allows remote authenticated guest users to execute arbitrary commands via shell metacharacters in the X-Forwarded-For HTTP header to photo/login.php. Synology Photo Station en versiones anteriores a 6.3-2958 permite a los usuarios invitados autenticados remotos ejecutar comandos arbitrarios a través de metacaracteres de shell en el encabezado HTTP X-Forwarded-For a photo/login.php. • http://seclists.org/oss-sec/2016/q1/236 https://www.synology.com/en-us/releaseNote/PhotoStation • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •
CVE-2015-4656
https://notcve.org/view.php?id=CVE-2015-4656
Multiple cross-site scripting (XSS) vulnerabilities in Synology Photo Station before 6.3-2945 allow remote attackers to inject arbitrary web script or HTML via the (1) success parameter to login.php or (2) crafted URL parameters to index.php, as demonstrated by the t parameter to photo/. Múltiples vulnerabilidades de XSS en Synology Photo Station anterior a 6.3-2945 permiten a atacantes remotos inyectar secuencias de comandos web arbitrarios o HTML a través (1) del parámetro success en login.php o (2) de parámetros URL manipulados en index.php, tal y como fue demostrado por el parámetro t en photo/. • http://seclists.org/fulldisclosure/2015/May/110 http://www.securityfocus.com/bid/74816 https://www.securify.nl/advisory/SFY20150504/synology_photo_station_multiple_cross_site_scripting_vulnerabilities.html https://www.synology.com/en-us/support/security/Photo_Station_2945 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2012-1556 – Synology Photo Station 5 DSM 3.2 - 'photo_one.php' Script Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2012-1556
Cross-site scripting (XSS) vulnerability in Synology Photo Station 5 for DiskStation Manager (DSM) 3.2-1955 allows remote attackers to inject arbitrary web script or HTML via the name parameter to photo/photo_one.php. Vulnerabilidad de XSS en Synology Photo Station 5 para DiskStation Manager (DSM) 3.2-1955 permite a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a través del parámetro name en photo/photo_one.php. Photo Station 5 suffers from a reflective cross site scripting vulnerability. • https://www.exploit-db.com/exploits/36944 http://archives.neohapsis.com/archives/bugtraq/2012-03/0045.html http://osvdb.org/80034 http://secunia.com/advisories/48334 http://www.securityfocus.com/bid/52416 https://exchange.xforce.ibmcloud.com/vulnerabilities/73976 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •