CVE-2016-10329
critical
CVSS v3
9.8
CVSS v2
7.5
VIR risk
9.8
Description
Command injection vulnerability in login.php in Synology Photo Station before 6.5.3-3226 allows remote attackers to execute arbitrary code via shell metacharacters in the crafted 'X-Forwarded-For' header.
Predictions
Exploit likelihood
97%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: security@synology.com — https://www.synology.com/en-global/support/security/Photo_Station_6_5_3_3226
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| synology | photo_station | {"endIncluding":"6.5.2-3225"} | |
References
- http://seclists.org/oss-sec/2016/q1/236
- https://bamboofox.github.io/2017/03/20/Synology-Bug-Bounty-2016/#Vul-01-PhotoStation-Login-without-password
- https://bamboofox.github.io/2017/03/20/Synology-Bug-Bounty-2016/#Vul-02-PhotoStation-Remote-Code-Execution
- https://www.synology.com/en-global/support/security/Photo_Station_6_5_3_3226
- http://seclists.org/oss-sec/2016/q1/236
- https://bamboofox.github.io/2017/03/20/Synology-Bug-Bounty-2016/#Vul-01-PhotoStation-Login-without-password
- https://bamboofox.github.io/2017/03/20/Synology-Bug-Bounty-2016/#Vul-02-PhotoStation-Remote-Code-Execution
- https://www.synology.com/en-global/support/security/Photo_Station_6_5_3_3226
CWEs
CWE-77
Verify integrity in audit chain (admin only). AS-IS.