Lucene search

K

Photo Station Security Vulnerabilities

cve
cve

CVE-2023-47221

A path traversal vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow authenticated administrators to read the contents of unexpected files and expose sensitive data via a network. We have already fixed the vulnerability in the following version:...

5.5CVSS

5.2AI Score

0.0004EPSS

2024-03-08 05:15 PM
30
cve
cve

CVE-2023-47562

An OS command injection vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow authenticated users to execute commands via a network. We have already fixed the vulnerability in the following version: Photo Station 6.4.2 ( 2023/12/15 ) and...

8.8CVSS

8.8AI Score

0.0005EPSS

2024-02-02 04:15 PM
11
cve
cve

CVE-2023-47561

A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following version: Photo Station 6.4.2 ( 2023/12/15 ) and...

5.5CVSS

5.6AI Score

0.0004EPSS

2024-02-02 04:15 PM
11
cve
cve

CVE-2016-10322

Synology Photo Station before 6.3-2958 allows remote authenticated guest users to execute arbitrary commands via shell metacharacters in the X-Forwarded-For HTTP header to...

8.8CVSS

8.7AI Score

0.001EPSS

2022-10-03 04:16 PM
22
cve
cve

CVE-2016-10323

Synology Photo Station before 6.3-2958 allows local users to gain privileges by leveraging setuid execution of a "synophoto_dsm_user --copy-no-ea"...

7.8CVSS

7.6AI Score

0.0004EPSS

2022-10-03 04:16 PM
28
cve
cve

CVE-2022-27593

An externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, This could allow an attacker to modify system files. We have already fixed the vulnerability in the following versions: QTS 5.0.1: Photo Station 6.1.2 and later.....

10CVSS

8.9AI Score

0.571EPSS

2022-09-08 11:15 AM
602
In Wild
8
cve
cve

CVE-2022-22681

Session fixation vulnerability in access control management in Synology Photo Station before 6.8.16-3506 allows remote attackers to bypass security constraint via unspecified...

8.1CVSS

7.5AI Score

0.001EPSS

2022-07-06 08:15 AM
38
7
cve
cve

CVE-2021-44057

An improper authentication vulnerability has been reported to affect QNAP device running Photo Station. If exploited, this vulnerability allows attackers to compromise the security of the system. We have already fixed this vulnerability in the following versions of Photo Station: Photo Station...

9.8CVSS

9.5AI Score

0.002EPSS

2022-05-06 12:00 AM
83
4
cve
cve

CVE-2021-34354

A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Photo Station. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Photo Station: Photo Station 6.0.18 (...

7.6CVSS

5.2AI Score

0.001EPSS

2021-10-01 03:15 AM
27
cve
cve

CVE-2021-34355

A cross-site scripting (XSS) vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Photo Station: Photo Station 5.4.10 (...

7.6CVSS

5.3AI Score

0.001EPSS

2021-10-01 03:15 AM
21
cve
cve

CVE-2021-34356

A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Photo Station. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Photo Station: Photo Station 6.0.18 (...

7.6CVSS

5.2AI Score

0.001EPSS

2021-10-01 03:15 AM
25
cve
cve

CVE-2021-29089

Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in thumbnail component in Synology Photo Station before 6.8.14-3500 allows remote attackers users to execute arbitrary SQL commands via unspecified...

9.8CVSS

9.8AI Score

0.001EPSS

2021-06-02 03:15 AM
65
2
cve
cve

CVE-2021-29091

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in file management component in Synology Photo Station before 6.8.14-3500 allows remote authenticated users to write arbitrary files via unspecified...

7.7CVSS

6.1AI Score

0.001EPSS

2021-06-02 02:15 AM
61
5
cve
cve

CVE-2021-29090

Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in PHP component in Synology Photo Station before 6.8.14-3500 allows remote authenticated users to execute arbitrary SQL command via unspecified...

7.2CVSS

7.2AI Score

0.001EPSS

2021-06-02 02:15 AM
61
4
cve
cve

CVE-2021-29092

Unrestricted upload of file with dangerous type vulnerability in file management component in Synology Photo Station before 6.8.14-3500 allows remote authenticated users to execute arbitrary code via unspecified...

8.8CVSS

8.6AI Score

0.001EPSS

2021-06-01 02:15 PM
129
cve
cve

CVE-2020-2502

This cross-site scripting vulnerability in Photo Station allows remote attackers to inject malicious code. QANP We have already fixed this vulnerability in the following versions of Photo Station. Photo Station 6.0.11 and...

6.1CVSS

6AI Score

0.001EPSS

2021-02-17 04:15 AM
53
cve
cve

CVE-2020-2491

This cross-site scripting vulnerability in Photo Station allows remote attackers to inject malicious code. QANP We have already fixed this vulnerability in the following versions of Photo Station. QTS 4.5.1: Photo Station 6.0.12 and later QTS 4.4.3: Photo Station 6.0.12 and later QTS 4.3.6: Photo.....

6.1CVSS

6AI Score

0.001EPSS

2020-12-10 04:15 AM
32
cve
cve

CVE-2018-19955

The cross-site scripting vulnerability has been reported to affect earlier versions of Photo Station. If exploited, the vulnerability could allow remote attackers to inject malicious code. This issue affects: QNAP Systems Inc. Photo Station versions prior to 5.7.11; versions prior to...

6.1CVSS

6AI Score

0.001EPSS

2020-11-02 04:15 PM
13
cve
cve

CVE-2018-19954

The cross-site scripting vulnerability has been reported to affect earlier versions of Photo Station. If exploited, the vulnerability could allow remote attackers to inject malicious code. This issue affects: QNAP Systems Inc. Photo Station versions prior to 5.7.11; versions prior to...

6.1CVSS

6AI Score

0.001EPSS

2020-11-02 04:15 PM
18
cve
cve

CVE-2018-19956

The cross-site scripting vulnerability has been reported to affect earlier versions of Photo Station. If exploited, the vulnerability could allow remote attackers to inject malicious code. This issue affects: QNAP Systems Inc. Photo Station versions prior to 5.7.11; versions prior to...

6.1CVSS

6AI Score

0.001EPSS

2020-11-02 04:15 PM
16
cve
cve

CVE-2019-7195

This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest...

9.8CVSS

9.3AI Score

0.971EPSS

2019-12-05 05:15 PM
909
In Wild
6
cve
cve

CVE-2019-7194

This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest...

9.8CVSS

9.3AI Score

0.971EPSS

2019-12-05 05:15 PM
913
In Wild
cve
cve

CVE-2019-7192

This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix these vulnerabilities, QNAP recommend updating Photo Station to their latest...

9.8CVSS

9.4AI Score

0.963EPSS

2019-12-05 05:15 PM
1016
In Wild
cve
cve

CVE-2019-11821

SQL injection vulnerability in synophoto_csPhotoDB.php in Synology Photo Station before 6.8.11-3489 and before 6.3-2977 allows remote attackers to execute arbitrary SQL command via the type...

9.8CVSS

9.9AI Score

0.001EPSS

2019-06-30 03:15 PM
47
cve
cve

CVE-2019-11822

Relative path traversal vulnerability in SYNO.PhotoStation.File in Synology Photo Station before 6.8.11-3489 and before 6.3-2977 allows remote attackers to upload arbitrary files via the uploadphoto...

6.5CVSS

6.6AI Score

0.001EPSS

2019-06-30 03:15 PM
52
cve
cve

CVE-2018-0722

Path Traversal vulnerability in Photo Station versions: 5.7.2 and earlier in QTS 4.3.4, 5.4.4 and earlier in QTS 4.3.3, 5.2.8 and earlier in QTS 4.2.6 could allow remote attackers to access sensitive information on the...

7.5CVSS

7.3AI Score

0.003EPSS

2019-02-01 06:29 PM
22
cve
cve

CVE-2018-13282

Session fixation vulnerability in SYNO.PhotoStation.Auth in Synology Photo Station before 6.8.7-3481 allows remote attackers to hijack web sessions via the PHPSESSID...

6.3CVSS

6.3AI Score

0.001EPSS

2018-10-31 04:29 PM
18
cve
cve

CVE-2018-0715

Cross-site scripting vulnerability in QNAP Photo Station versions 5.7.0 and earlier could allow remote attackers to inject Javascript code in the compromised...

6.1CVSS

6.1AI Score

0.006EPSS

2018-08-27 01:29 PM
51
cve
cve

CVE-2018-8926

Permissive regular expression vulnerability in synophoto_dsm_user in Synology Photo Station before 6.8.5-3471 and before 6.3-2975 allows remote authenticated users to conduct privilege escalation attacks via the fullname...

8.8CVSS

8.5AI Score

0.001EPSS

2018-06-08 01:29 PM
19
cve
cve

CVE-2018-8925

Cross-site request forgery (CSRF) vulnerability in admin/user.php in Synology Photo Station before 6.8.5-3471 and before 6.3-2975 allows remote attackers to hijack the authentication of administrators via the (1) username, (2) password, (3) admin, (4) action, (5) uid, or (6) modify_admin...

8.8CVSS

8.9AI Score

0.001EPSS

2018-06-08 01:29 PM
22
cve
cve

CVE-2017-13073

Cross-site scripting (XSS) vulnerability in QNAP NAS application Photo Station versions 5.2.7, 5.4.3, and their earlier versions could allow remote attackers to inject arbitrary web script or...

6.1CVSS

6AI Score

0.001EPSS

2018-04-23 02:29 PM
24
cve
cve

CVE-2017-16771

Cross-site scripting (XSS) vulnerability in Log Viewer in Synology Photo Station before 6.8.3-3463 and before 6.3-2971 allows remote attackers to inject arbitrary web script or HTML via the username...

6.1CVSS

6AI Score

0.001EPSS

2018-03-22 02:29 PM
23
cve
cve

CVE-2017-16772

Improper input validation vulnerability in SYNOPHOTO_Flickr_MultiUpload in Synology Photo Station before 6.8.3-3463 and before 6.3-2971 allows remote authenticated users to execute arbitrary codes via the prog_id...

8.8CVSS

8.5AI Score

0.001EPSS

2018-03-22 02:29 PM
25
cve
cve

CVE-2017-16769

Exposure of private information vulnerability in Photo Viewer in Synology Photo Station 6.8.1-3458 allows remote attackers to obtain metadata from password-protected photographs via the map viewer...

5.3CVSS

5.2AI Score

0.001EPSS

2018-02-23 10:29 PM
24
cve
cve

CVE-2017-12072

Cross-site scripting (XSS) vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.8.0-3456 allows remote authenticated users to inject arbitrary web scripts or HTML via the id...

5.4CVSS

5.1AI Score

0.001EPSS

2017-12-20 06:29 PM
27
cve
cve

CVE-2017-12080

An information exposure vulnerability in default HTTP configuration file in Synology Photo Station before 6.8.1-3458 and before 6.3-2970 allows remote attackers to obtain sensitive system information via .htaccess...

5.3CVSS

5.1AI Score

0.001EPSS

2017-12-04 07:29 PM
22
cve
cve

CVE-2017-12079

Files or directories accessible to external parties vulnerability in picasa.php in Synology Photo Station before 6.8.1-3458 and before 6.3-2970 allows remote attackers to obtain arbitrary files via prog_id...

7.5CVSS

7.5AI Score

0.001EPSS

2017-12-04 07:29 PM
31
cve
cve

CVE-2017-12071

Server-side request forgery (SSRF) vulnerability in file_upload.php in Synology Photo Station before 6.7.4-3433 and 6.3-2968 allows remote authenticated users to download arbitrary local files via the url...

6.5CVSS

6.8AI Score

0.001EPSS

2017-09-08 02:29 PM
27
cve
cve

CVE-2017-11162

Directory traversal vulnerability in synphotoio in Synology Photo Station before 6.7.4-3433 and 6.3-2968 allows remote authenticated users to read arbitrary files via unspecified...

6.5CVSS

6.6AI Score

0.001EPSS

2017-09-08 02:29 PM
24
cve
cve

CVE-2017-11161

Multiple SQL injection vulnerabilities in Synology Photo Station before 6.7.4-3433 and 6.3-2968 allow remote attackers to execute arbitrary SQL commands via the (1) article_id parameter to label.php; or (2) type parameter to...

9.8CVSS

10AI Score

0.001EPSS

2017-09-08 02:29 PM
32
cve
cve

CVE-2017-9555

Cross-site scripting (XSS) vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.7.0-3414 allows remote attackers to inject arbitrary web script or HTML via the image...

5.4CVSS

5.4AI Score

0.001EPSS

2017-08-24 07:29 PM
23
cve
cve

CVE-2017-11159

Multiple untrusted search path vulnerabilities in installer in Synology Photo Station Uploader before 1.4.2-084 on Windows allows local attackers to execute arbitrary code and conduct DLL hijacking attack via a Trojan horse (1) shfolder.dll, (2) ntmarta.dll, (3) secur32.dll or (4) dwmapi.dll file.....

7.8CVSS

7.8AI Score

0.001EPSS

2017-08-23 03:29 PM
687
cve
cve

CVE-2017-11154

Unrestricted file upload vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to create arbitrary PHP scripts via the type...

7.2CVSS

7.5AI Score

0.451EPSS

2017-08-08 03:29 PM
21
cve
cve

CVE-2017-11153

Deserialization vulnerability in synophoto_csPhotoMisc.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to gain administrator privileges via a crafted serialized...

9.8CVSS

9.3AI Score

0.803EPSS

2017-08-08 03:29 PM
30
cve
cve

CVE-2017-11151

A vulnerability in synotheme_upload.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to upload arbitrary files without authentication via the logo_upload...

9.8CVSS

9.5AI Score

0.61EPSS

2017-08-08 03:29 PM
28
cve
cve

CVE-2017-11155

An information exposure vulnerability in index.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to obtain sensitive system information via unspecified...

7.5CVSS

7.2AI Score

0.458EPSS

2017-08-08 03:29 PM
32
cve
cve

CVE-2017-11152

Directory traversal vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to write arbitrary files via the path...

7.5CVSS

7.9AI Score

0.002EPSS

2017-08-08 03:29 PM
21
cve
cve

CVE-2015-9102

Multiple cross-site scripting (XSS) vulnerabilities in Synology Photo Station 6.0 before 6.0-2638 and 6.3 before 6.3-2962 allow remote authenticated attackers to inject arbitrary web script or HTML via the (1) album name, (2) file name of uploaded photos, (3) description of photos, or (4) tag of...

5.4CVSS

5.1AI Score

0.002EPSS

2017-06-30 01:29 PM
18
cve
cve

CVE-2017-9552

A design flaw in authentication in Synology Photo Station 6.0-2528 through 6.7.1-3419 allows local users to obtain credentials via cmdline. Synology Photo Station employs the synophoto_dsm_user program to authenticate username and password by "synophoto_dsm_user --auth USERNAME PASSWORD", and...

7.8CVSS

7.6AI Score

0.0004EPSS

2017-06-13 01:29 PM
20
cve
cve

CVE-2016-10330

Directory traversal vulnerability in synophoto_dsm_user, a SUID program, as used in Synology Photo Station before 6.5.3-3226 allows local users to write to arbitrary files via unspecified...

7.1CVSS

6.7AI Score

0.0004EPSS

2017-05-12 08:29 PM
17
Total number of security vulnerabilities55