CVE-2015-6912: Command Injection
Published Sep 11, 2015
·Updated
Synology Video Station before 1.5-0763 allows remote attackers to execute arbitrary shell commands via shell metacharacters in the subtitlecodepage parameter to subtitle.cgi.
Affected Software
1 affected component
Synology Video Station<=1.5-0757
Event History
Sep 11, 2015
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-6912?
CVE-2015-6912 is categorized as a critical vulnerability due to its potential to allow remote command execution.
2
How do I fix CVE-2015-6912?
To mitigate CVE-2015-6912, it is recommended to upgrade to Synology Video Station version 1.5-0763 or later.
3
What impact does CVE-2015-6912 have on my system?
CVE-2015-6912 can lead to unauthorized remote execution of arbitrary shell commands, compromising the affected system.
4
In which versions of Synology Video Station is CVE-2015-6912 present?
CVE-2015-6912 affects Synology Video Station versions prior to 1.5-0763, specifically those up to version 1.5-0757.
5
Is CVE-2015-6912 a local or remote vulnerability?
CVE-2015-6912 is a remote vulnerability, allowing attackers to exploit it without physical access to the affected system.