CVE-2010-2453: XSS
Multiple cross-site scripting (XSS) vulnerabilities in Synology Disk Station 2.x before DSM3.0-1337 allow remote attackers to inject arbitrary web script or HTML by connecting to the FTP server and providing a crafted (1) USER or (2) PASS command, which is written by the FTP logging module to a web-interface log window, related to a "web commands injection" issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-2453?
CVE-2010-2453 has a medium severity rating, primarily due to the ability for remote attackers to execute arbitrary web scripts.
How do I fix CVE-2010-2453?
To mitigate CVE-2010-2453, upgrade to DSM version 3.0-1337 or later to patch the XSS vulnerabilities.
What are the affected versions for CVE-2010-2453?
CVE-2010-2453 affects Synology Disk Station Manager versions 2.x before DSM3.0-1337.
How can CVE-2010-2453 be exploited?
CVE-2010-2453 can be exploited by sending crafted USER or PASS commands to the FTP server to inject arbitrary web scripts.
What are the potential impacts of CVE-2010-2453?
The potential impacts of CVE-2010-2453 include unauthorized access to user sessions or web content through XSS attacks.