Synology Photo Station vulnerabilities
19 known vulnerabilities affecting synology/synology_photo_station.
Total CVEs
19
CISA KEV
0
Public exploits
6
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH8MEDIUM6
Vulnerabilities
Page 1 of 1
CVE-2021-29089CRITICALCVSS 9.8≥ unspecified, < 6.8.14-35002021-06-02
CVE-2021-29089 [CRITICAL] CWE-89 CVE-2021-29089: Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability i
Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in thumbnail component in Synology Photo Station before 6.8.14-3500 allows remote attackers users to execute arbitrary SQL commands via unspecified vectors.
cvelistv5nvd
CVE-2021-29090HIGHCVSS 7.2≥ unspecified, < 6.8.14-35002021-06-02
CVE-2021-29090 [HIGH] CWE-89 CVE-2021-29090: Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability i
Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in PHP component in Synology Photo Station before 6.8.14-3500 allows remote authenticated users to execute arbitrary SQL command via unspecified vectors.
cvelistv5nvd
CVE-2021-29091MEDIUMCVSS 6.5≥ unspecified, < 6.8.14-35002021-06-02
CVE-2021-29091 [MEDIUM] CWE-22 CVE-2021-29091: Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in file
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in file management component in Synology Photo Station before 6.8.14-3500 allows remote authenticated users to write arbitrary files via unspecified vectors.
cvelistv5nvd
CVE-2021-29092HIGHCVSS 8.8≥ unspecified, < 6.8.14-35002021-06-01
CVE-2021-29092 [HIGH] CWE-434 CVE-2021-29092: Unrestricted upload of file with dangerous type vulnerability in file management component in Synolo
Unrestricted upload of file with dangerous type vulnerability in file management component in Synology Photo Station before 6.8.14-3500 allows remote authenticated users to execute arbitrary code via unspecified vectors.
cvelistv5nvd
CVE-2017-16769MEDIUMCVSS 5.3v6.8.1-34582018-02-23
CVE-2017-16769 [MEDIUM] CWE-359 CVE-2017-16769: Exposure of private information vulnerability in Photo Viewer in Synology Photo Station 6.8.1-3458 a
Exposure of private information vulnerability in Photo Viewer in Synology Photo Station 6.8.1-3458 allows remote attackers to obtain metadata from password-protected photographs via the map viewer mode.
cvelistv5nvd
CVE-2017-11161CRITICALCVSS 9.8vbefore 6.7.4-3433 and 6.3-29682017-09-08
CVE-2017-11161 [CRITICAL] CWE-89 CVE-2017-11161: Multiple SQL injection vulnerabilities in Synology Photo Station before 6.7.4-3433 and 6.3-2968 allo
Multiple SQL injection vulnerabilities in Synology Photo Station before 6.7.4-3433 and 6.3-2968 allow remote attackers to execute arbitrary SQL commands via the (1) article_id parameter to label.php; or (2) type parameter to synotheme.php.
cvelistv5nvd
CVE-2017-12071MEDIUMCVSS 6.5vbefore 6.7.4-3433 and 6.3-29682017-09-08
CVE-2017-12071 [MEDIUM] CWE-918 CVE-2017-12071: Server-side request forgery (SSRF) vulnerability in file_upload.php in Synology Photo Station before
Server-side request forgery (SSRF) vulnerability in file_upload.php in Synology Photo Station before 6.7.4-3433 and 6.3-2968 allows remote authenticated users to download arbitrary local files via the url parameter.
cvelistv5nvd
CVE-2017-11162MEDIUMCVSS 6.5vbefore 6.7.4-3433 and 6.3-29682017-09-08
CVE-2017-11162 [MEDIUM] CWE-22 CVE-2017-11162: Directory traversal vulnerability in synphotoio in Synology Photo Station before 6.7.4-3433 and 6.3-
Directory traversal vulnerability in synphotoio in Synology Photo Station before 6.7.4-3433 and 6.3-2968 allows remote authenticated users to read arbitrary files via unspecified vectors.
cvelistv5nvd
CVE-2017-9555MEDIUMCVSS 5.4vbefore 6.7.0-34142017-08-24
CVE-2017-9555 [MEDIUM] CWE-79 CVE-2017-9555: Cross-site scripting (XSS) vulnerability in PixlrEditorHandler.php in Synology Photo Station before
Cross-site scripting (XSS) vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.7.0-3414 allows remote attackers to inject arbitrary web script or HTML via the image parameter.
cvelistv5nvd
CVE-2017-11151CRITICALCVSS 9.8PoCvbefore 6.7.3-3432 and 6.3-29672017-08-08
CVE-2017-11151 [CRITICAL] CWE-287 CVE-2017-11151: A vulnerability in synotheme_upload.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 all
A vulnerability in synotheme_upload.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to upload arbitrary files without authentication via the logo_upload action.
cvelistv5nvd
CVE-2017-11153CRITICALCVSS 9.8PoCvbefore 6.7.3-3432 and 6.3-29672017-08-08
CVE-2017-11153 [CRITICAL] CWE-502 CVE-2017-11153: Deserialization vulnerability in synophoto_csPhotoMisc.php in Synology Photo Station before 6.7.3-34
Deserialization vulnerability in synophoto_csPhotoMisc.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to gain administrator privileges via a crafted serialized payload.
cvelistv5nvd
CVE-2017-11154HIGHCVSS 7.2PoCvbefore 6.7.3-3432 and 6.3-29672017-08-08
CVE-2017-11154 [HIGH] CWE-434 CVE-2017-11154: Unrestricted file upload vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.
Unrestricted file upload vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to create arbitrary PHP scripts via the type parameter.
cvelistv5nvd
CVE-2017-11152HIGHCVSS 7.5PoCvbefore 6.7.3-3432 and 6.3-29672017-08-08
CVE-2017-11152 [HIGH] CWE-22 CVE-2017-11152: Directory traversal vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.7.3-3
Directory traversal vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to write arbitrary files via the path parameter.
cvelistv5nvd
CVE-2017-11155HIGHCVSS 7.5PoCvbefore 6.7.3-3432 and 6.3-29672017-08-08
CVE-2017-11155 [HIGH] CWE-205 CVE-2017-11155: An information exposure vulnerability in index.php in Synology Photo Station before 6.7.3-3432 and 6
An information exposure vulnerability in index.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to obtain sensitive system information via unspecified vectors.
cvelistv5nvd
CVE-2017-9552HIGHCVSS 7.8v6.0-2528 through 6.7.1-34192017-06-13
CVE-2017-9552 [HIGH] CWE-522 CVE-2017-9552: A design flaw in authentication in Synology Photo Station 6.0-2528 through 6.7.1-3419 allows local u
A design flaw in authentication in Synology Photo Station 6.0-2528 through 6.7.1-3419 allows local users to obtain credentials via cmdline. Synology Photo Station employs the synophoto_dsm_user program to authenticate username and password by "synophoto_dsm_user --auth USERNAME PASSWORD", and local users are able to obtain credentials by sniffing "/proc
cvelistv5nvd
CVE-2016-10329CRITICALCVSS 9.8vAll versions prior to version 6.5.3-32262017-05-12
CVE-2016-10329 [CRITICAL] CWE-77 CVE-2016-10329: Command injection vulnerability in login.php in Synology Photo Station before 6.5.3-3226 allows remo
Command injection vulnerability in login.php in Synology Photo Station before 6.5.3-3226 allows remote attackers to execute arbitrary code via shell metacharacters in the crafted 'X-Forwarded-For' header.
cvelistv5nvd
CVE-2016-10330HIGHCVSS 7.1vAll versions prior to version 6.5.3-32262017-05-12
CVE-2016-10330 [HIGH] CWE-22 CVE-2016-10330: Directory traversal vulnerability in synophoto_dsm_user, a SUID program, as used in Synology Photo S
Directory traversal vulnerability in synophoto_dsm_user, a SUID program, as used in Synology Photo Station before 6.5.3-3226 allows local users to write to arbitrary files via unspecified vectors.
cvelistv5nvd
CVE-2016-10331HIGHCVSS 7.5vAll versions prior to version 6.5.3-32262017-05-12
CVE-2016-10331 [HIGH] CWE-22 CVE-2016-10331: Directory traversal vulnerability in download.php in Synology Photo Station before 6.5.3-3226 allows
Directory traversal vulnerability in download.php in Synology Photo Station before 6.5.3-3226 allows remote attackers to read arbitrary files via a full pathname in the id parameter.
cvelistv5nvd
CVE-2012-1556MEDIUMCVSS 4.3PoCv52014-09-12
CVE-2012-1556 [MEDIUM] CWE-79 CVE-2012-1556: Cross-site scripting (XSS) vulnerability in Synology Photo Station 5 for DiskStation Manager (DSM) 3
Cross-site scripting (XSS) vulnerability in Synology Photo Station 5 for DiskStation Manager (DSM) 3.2-1955 allows remote attackers to inject arbitrary web script or HTML via the name parameter to photo/photo_one.php.
nvd