CVE-2015-6909: XSS
Published Sep 11, 2015
·Updated
Cross-site scripting (XSS) vulnerability in the "Create download task via file upload" feature in Synology Download Station before 3.5-2962 allows remote attackers to inject arbitrary web script or HTML via the name element in the Info dictionary in a torrent file.
Affected Software
1 affected component
Synology Download Station<=3.5-2956
Event History
Sep 11, 2015
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-6909?
CVE-2015-6909 is classified as a medium severity vulnerability due to the potential for remote exploitation.
2
How do I fix CVE-2015-6909?
To fix CVE-2015-6909, you should update Synology Download Station to version 3.5-2962 or later.
3
Who is affected by CVE-2015-6909?
CVE-2015-6909 affects all versions of Synology Download Station prior to 3.5-2962.
4
What type of vulnerability is CVE-2015-6909?
CVE-2015-6909 is a cross-site scripting (XSS) vulnerability.
5
What can an attacker do with CVE-2015-6909?
An attacker can inject arbitrary web script or HTML into the application through the name element in a torrent file.