Synology Photo Station 'list' Parameter Arbitrary File Disclosure Vulnerability
BID:56674
Info
Synology Photo Station 'list' Parameter Arbitrary File Disclosure Vulnerability
| Bugtraq ID: | 56674 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 26 2012 12:00AM |
| Updated: | Nov 26 2012 12:00AM |
| Credit: | Julien Cayssol |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Synology Photo Station 'list' Parameter Arbitrary File Disclosure Vulnerability
Synology Photo Station is prone to an arbitrary file-disclosure vulnerability because it fails to properly sanitize user-supplied input.
A remote attacker can use directory-traversal sequences to retrieve arbitrary files in the context of the affected application.
Synology Photo Station is prone to an arbitrary file-disclosure vulnerability because it fails to properly sanitize user-supplied input.
A remote attacker can use directory-traversal sequences to retrieve arbitrary files in the context of the affected application.
Exploit / POC
Synology Photo Station 'list' Parameter Arbitrary File Disclosure Vulnerability
Attackers can exploit this issue with a browser.
Attackers can exploit this issue with a browser.
Solution / Fix
Synology Photo Station 'list' Parameter Arbitrary File Disclosure Vulnerability
Solution:
Reportedly, the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reportedly, the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
References
Synology Photo Station 'list' Parameter Arbitrary File Disclosure Vulnerability
References:
References:
- Synology Photo Station Homepage (Synology )