Synology DiskStation Manager FTP Log Multiple HTML Injection Vulnerabilities
BID:43542
Info
Synology DiskStation Manager FTP Log Multiple HTML Injection Vulnerabilities
| Bugtraq ID: | 43542 |
| Class: | Input Validation Error |
| CVE: |
CVE-2010-2453 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 28 2010 12:00AM |
| Updated: | Sep 28 2010 12:00AM |
| Credit: | Rodrigo Rubira Branco, Check Point Vulnerability Discovery Team (VDT) and Aditya K. Sood, Secniche |
| Vulnerable: |
Synology Synology DiskStation Manager 2.X |
| Not Vulnerable: | |
Discussion
Synology DiskStation Manager FTP Log Multiple HTML Injection Vulnerabilities
Synology DiskStation Manager is prone to multiple HTML-injection vulnerabilities because the device's web-based administration application fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
Synology DiskStation Manager 2.x is vulnerable; other versions may also be affected.
Synology DiskStation Manager is prone to multiple HTML-injection vulnerabilities because the device's web-based administration application fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
Synology DiskStation Manager 2.x is vulnerable; other versions may also be affected.
Exploit / POC
Synology DiskStation Manager FTP Log Multiple HTML Injection Vulnerabilities
Attackers can use standard, readily available tools to exploit these issues.
Attackers can use standard, readily available tools to exploit these issues.
Solution / Fix
Synology DiskStation Manager FTP Log Multiple HTML Injection Vulnerabilities
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
Synology DiskStation Manager FTP Log Multiple HTML Injection Vulnerabilities
References:
References:
- Homepage (Synology Inc)