Synology
Synology Photo Station: vulnerabilidades y CVE
Synology Photo Station tiene 33 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 6 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE33
Últimos 12 meses0
Críticas6
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-22681 | Alta (7.5) | 1.0% | — | 6 jul 2022 | Session fixation vulnerability in access control management in Synology Photo Station before 6.8.16-3506 allows remote attackers to bypass security constraint via unspecified vectors. |
| CVE-2021-29089 | Crítica (9.8) | 1.9% | — | 2 jun 2021 | Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in thumbnail component in Synology Photo Station before 6.8.14-3500 allows remote attackers users to execute arbitrary… |
| CVE-2021-29091 | Media (6.5) | 1.1% | — | 2 jun 2021 | Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in file management component in Synology Photo Station before 6.8.14-3500 allows remote authenticated users to write arbitrary… |
| CVE-2021-29090 | Alta (7.2) | 1.7% | — | 2 jun 2021 | Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in PHP component in Synology Photo Station before 6.8.14-3500 allows remote authenticated users to execute arbitrary SQL… |
| CVE-2021-29092 | Alta (8.8) | 1.7% | — | 1 jun 2021 | Unrestricted upload of file with dangerous type vulnerability in file management component in Synology Photo Station before 6.8.14-3500 allows remote authenticated users to execute arbitrary code via unspecified vectors. |
| CVE-2019-11822 | Media (6.5) | 1.3% | — | 30 jun 2019 | Relative path traversal vulnerability in SYNO.PhotoStation.File in Synology Photo Station before 6.8.11-3489 and before 6.3-2977 allows remote attackers to upload arbitrary files via the uploadphoto parameter. |
| CVE-2019-11821 | Crítica (9.8) | 1.7% | — | 30 jun 2019 | SQL injection vulnerability in synophoto_csPhotoDB.php in Synology Photo Station before 6.8.11-3489 and before 6.3-2977 allows remote attackers to execute arbitrary SQL command via the type parameter. |
| CVE-2018-13282 | Media (6.3) | 0.96% | — | 31 oct 2018 | Session fixation vulnerability in SYNO.PhotoStation.Auth in Synology Photo Station before 6.8.7-3481 allows remote attackers to hijack web sessions via the PHPSESSID parameter. |
| CVE-2018-8926 | Alta (8.8) | 1.7% | — | 8 jun 2018 | Permissive regular expression vulnerability in synophoto_dsm_user in Synology Photo Station before 6.8.5-3471 and before 6.3-2975 allows remote authenticated users to conduct privilege escalation attacks via the… |
| CVE-2018-8925 | Alta (8.8) | 0.73% | — | 8 jun 2018 | Cross-site request forgery (CSRF) vulnerability in admin/user.php in Synology Photo Station before 6.8.5-3471 and before 6.3-2975 allows remote attackers to hijack the authentication of administrators via the (1)… |
| CVE-2017-16772 | Alta (8.8) | 3.2% | — | 22 mar 2018 | Improper input validation vulnerability in SYNOPHOTO_Flickr_MultiUpload in Synology Photo Station before 6.8.3-3463 and before 6.3-2971 allows remote authenticated users to execute arbitrary codes via the prog_id… |
| CVE-2017-16771 | Media (6.1) | 1.3% | — | 22 mar 2018 | Cross-site scripting (XSS) vulnerability in Log Viewer in Synology Photo Station before 6.8.3-3463 and before 6.3-2971 allows remote attackers to inject arbitrary web script or HTML via the username parameter. |
| CVE-2017-16769 | Media (5.3) | 1.9% | — | 23 feb 2018 | Exposure of private information vulnerability in Photo Viewer in Synology Photo Station 6.8.1-3458 allows remote attackers to obtain metadata from password-protected photographs via the map viewer mode. |
| CVE-2017-12072 | Media (5.4) | 1.0% | — | 20 dic 2017 | Cross-site scripting (XSS) vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.8.0-3456 allows remote authenticated users to inject arbitrary web scripts or HTML via the id parameter. |
| CVE-2017-12080 | Media (5.3) | 1.4% | — | 4 dic 2017 | An information exposure vulnerability in default HTTP configuration file in Synology Photo Station before 6.8.1-3458 and before 6.3-2970 allows remote attackers to obtain sensitive system information via .htaccess file. |
| CVE-2017-12079 | Alta (7.5) | 1.8% | — | 4 dic 2017 | Files or directories accessible to external parties vulnerability in picasa.php in Synology Photo Station before 6.8.1-3458 and before 6.3-2970 allows remote attackers to obtain arbitrary files via prog_id field. |
| CVE-2017-12071 | Media (6.5) | 1.4% | — | 8 sept 2017 | Server-side request forgery (SSRF) vulnerability in file_upload.php in Synology Photo Station before 6.7.4-3433 and 6.3-2968 allows remote authenticated users to download arbitrary local files via the url parameter. |
| CVE-2017-11162 | Media (6.5) | 1.6% | — | 8 sept 2017 | Directory traversal vulnerability in synphotoio in Synology Photo Station before 6.7.4-3433 and 6.3-2968 allows remote authenticated users to read arbitrary files via unspecified vectors. |
| CVE-2017-11161 | Crítica (9.8) | 1.2% | — | 8 sept 2017 | Multiple SQL injection vulnerabilities in Synology Photo Station before 6.7.4-3433 and 6.3-2968 allow remote attackers to execute arbitrary SQL commands via the (1) article_id parameter to label.php; or (2) type… |
| CVE-2017-9555 | Media (5.4) | 0.79% | — | 24 ago 2017 | Cross-site scripting (XSS) vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.7.0-3414 allows remote attackers to inject arbitrary web script or HTML via the image parameter. |
| CVE-2017-11155 | Alta (7.5) | 47% | — | 8 ago 2017 | An information exposure vulnerability in index.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to obtain sensitive system information via unspecified vectors. |
| CVE-2017-11154 | Alta (7.2) | 8.6% | — | 8 ago 2017 | Unrestricted file upload vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to create arbitrary PHP scripts via the type parameter. |
| CVE-2017-11153 | Crítica (9.8) | 12% | — | 8 ago 2017 | Deserialization vulnerability in synophoto_csPhotoMisc.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to gain administrator privileges via a crafted serialized payload. |
| CVE-2017-11152 | Alta (7.5) | 15% | — | 8 ago 2017 | Directory traversal vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to write arbitrary files via the path parameter. |
| CVE-2017-11151 | Crítica (9.8) | 16% | — | 8 ago 2017 | A vulnerability in synotheme_upload.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to upload arbitrary files without authentication via the logo_upload action. |
| CVE-2015-9102 | Media (5.4) | 0.89% | — | 30 jun 2017 | Multiple cross-site scripting (XSS) vulnerabilities in Synology Photo Station 6.0 before 6.0-2638 and 6.3 before 6.3-2962 allow remote authenticated attackers to inject arbitrary web script or HTML via the (1) album… |
| CVE-2017-9552 | Alta (7.8) | 0.31% | — | 13 jun 2017 | A design flaw in authentication in Synology Photo Station 6.0-2528 through 6.7.1-3419 allows local users to obtain credentials via cmdline. Synology Photo Station employs the synophoto_dsm_user program to authenticate… |
| CVE-2016-10331 | Alta (7.5) | 2.2% | — | 12 may 2017 | Directory traversal vulnerability in download.php in Synology Photo Station before 6.5.3-3226 allows remote attackers to read arbitrary files via a full pathname in the id parameter. |
| CVE-2016-10330 | Alta (7.1) | 0.69% | — | 12 may 2017 | Directory traversal vulnerability in synophoto_dsm_user, a SUID program, as used in Synology Photo Station before 6.5.3-3226 allows local users to write to arbitrary files via unspecified vectors. |
| CVE-2016-10329 | Crítica (9.8) | 41% | — | 12 may 2017 | Command injection vulnerability in login.php in Synology Photo Station before 6.5.3-3226 allows remote attackers to execute arbitrary code via shell metacharacters in the crafted 'X-Forwarded-For' header. |