First published: Thu Jan 09 2014(Updated: )
webman/imageSelector.cgi in Synology DiskStation Manager (DSM) 4.0 before 4.0-2259, 4.2 before 4.2-3243, and 4.3 before 4.3-3810 Update 1 allows remote attackers to append data to arbitrary files, and consequently execute arbitrary code, via a pathname in the SLICEUPLOAD X-TMP-FILE HTTP header.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Synology DiskStation Manager | =4.0 | |
Synology DiskStation Manager | =4.2 | |
Synology DiskStation Manager | =4.3 | |
Synology DiskStation Manager | =4.3-3810 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.