CVE-2016-10329: Command Injection
Published May 12, 2017
·Updated
Command injection vulnerability in login.php in Synology Photo Station before 6.5.3-3226 allows remote attackers to execute arbitrary code via shell metacharacters in the crafted 'X-Forwarded-For' header.
Affected Software
1 affected component
Synology Photo Station<=6.5.2-3225
Event History
May 12, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2016-10329?
CVE-2016-10329 is classified as a high severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2016-10329?
To mitigate CVE-2016-10329, upgrade Synology Photo Station to version 6.5.3-3226 or later.
3
What software is affected by CVE-2016-10329?
CVE-2016-10329 affects Synology Photo Station versions prior to 6.5.3-3226.
4
What kind of attack does CVE-2016-10329 allow?
CVE-2016-10329 allows remote attackers to perform command injection via a crafted 'X-Forwarded-For' header.
5
When was CVE-2016-10329 disclosed?
CVE-2016-10329 was disclosed in early 2016.