📦

photo_station

Vendor: synology

Actively Exploited 4 CISA KEV List
PoC / Exploits 8 Code Available
Total RCEs 6 Remote Access
Total CVEs 355 Total Indexed
Avg. EPSS 9.53% Exploit Prob.
Latest CVE CVE-2017-20210 Nov 11

Security Vulnerability Index

Page 5 / 36
7.5 CVSS

Files or directories accessible to external parties vulnerability in picasa.php in Synology Photo Station before 6.8.1-3458 and before 6.3-2970 allows remote attackers to obtain arbitrary files via prog_id field.

EPSS: 1.84%
6.5 CVSS

Server-side request forgery (SSRF) vulnerability in file_upload.php in Synology Photo Station before 6.7.4-3433 and 6.3-2968 allows remote authenticated users to download arbitrary local files via the url parameter.

EPSS: 1.37%
6.5 CVSS

Directory traversal vulnerability in synphotoio in Synology Photo Station before 6.7.4-3433 and 6.3-2968 allows remote authenticated users to read arbitrary files via unspecified vectors.

EPSS: 1.61%
9.8 CVSS

Multiple SQL injection vulnerabilities in Synology Photo Station before 6.7.4-3433 and 6.3-2968 allow remote attackers to execute arbitrary SQL commands via the (1) article_id parameter to label.php; or (2) type parameter to synotheme.php.

EPSS: 1.24%
5.4 CVSS

Cross-site scripting (XSS) vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.7.0-3414 allows remote attackers to inject arbitrary web script or HTML via the image parameter.

EPSS: 0.79%
7.5 CVSS
CVE-2017-11155
Exploit Found

An information exposure vulnerability in index.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to obtain sensitive system information via unspecified vectors.

EPSS: 44.57%
7.2 CVSS
CVE-2017-11154
RCE Exploit Found

Unrestricted file upload vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to create arbitrary PHP scripts via the type parameter.

EPSS: 14.22%
9.8 CVSS
CVE-2017-11153
RCE Exploit Found

Deserialization vulnerability in synophoto_csPhotoMisc.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to gain administrator privileges via a crafted serialized payload.

EPSS: 19.10%
7.5 CVSS
CVE-2017-11152
Exploit Found

Directory traversal vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to write arbitrary files via the path parameter.

EPSS: 13.91%
9.8 CVSS
CVE-2017-11151
Exploit Found

A vulnerability in synotheme_upload.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to upload arbitrary files without authentication via the logo_upload action.

EPSS: 25.26%