Synology DiskStation Manager Multiple Security Vulnerabilities
BID:62310
Info
Synology DiskStation Manager Multiple Security Vulnerabilities
| Bugtraq ID: | 62310 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 10 2013 12:00AM |
| Updated: | Sep 16 2013 12:12AM |
| Credit: | Andrea Fabrizi |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Synology DiskStation Manager Multiple Security Vulnerabilities
Synology DiskStation Manager is prone to a multiple security vulnerabilities, including:
1. A remote command-execution vulnerability
2. An arbitrary file-download vulnerability
3. Multiple cross-site scripting vulnerabilities
4. Multiple information-disclosure vulnerabilities
Exploiting these issues could allow an attacker to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, view and download arbitrary files from the web server, disclose sensitive information, or execute arbitrary commands in the context of the affected system.
Synology DiskStation Manager 4.3 and prior are vulnerable.
Synology DiskStation Manager is prone to a multiple security vulnerabilities, including:
1. A remote command-execution vulnerability
2. An arbitrary file-download vulnerability
3. Multiple cross-site scripting vulnerabilities
4. Multiple information-disclosure vulnerabilities
Exploiting these issues could allow an attacker to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, view and download arbitrary files from the web server, disclose sensitive information, or execute arbitrary commands in the context of the affected system.
Synology DiskStation Manager 4.3 and prior are vulnerable.
Exploit / POC
Synology DiskStation Manager Multiple Security Vulnerabilities
Attackers can use readily available tools to exploit these issues. An attacker can exploit cross-site scripting vulnerabilities by enticing an unsuspecting user to follow a malicious URI.
The researcher has created a proof-of-concept code. Please see the references for more information.
Attackers can use readily available tools to exploit these issues. An attacker can exploit cross-site scripting vulnerabilities by enticing an unsuspecting user to follow a malicious URI.
The researcher has created a proof-of-concept code. Please see the references for more information.
Solution / Fix
Synology DiskStation Manager Multiple Security Vulnerabilities
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are error or if you are aware of any more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are error or if you are aware of any more recent information, please mail us at: [email protected].
References
Synology DiskStation Manager Multiple Security Vulnerabilities
References:
References: