CVE-2016-10331: Path Traversal
Published May 12, 2017
·Updated
Directory traversal vulnerability in download.php in Synology Photo Station before 6.5.3-3226 allows remote attackers to read arbitrary files via a full pathname in the id parameter.
Affected Software
1 affected component
Synology Photo Station<=6.5.2-3225
Event History
May 12, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2016-10331?
CVE-2016-10331 is considered a high severity vulnerability due to its potential to allow unauthorized access to sensitive files.
2
How do I fix CVE-2016-10331?
To fix CVE-2016-10331, upgrade Synology Photo Station to version 6.5.3-3226 or later.
3
What systems are affected by CVE-2016-10331?
CVE-2016-10331 affects Synology Photo Station versions prior to 6.5.3-3226.
4
What type of attacks can CVE-2016-10331 facilitate?
CVE-2016-10331 can facilitate directory traversal attacks, allowing remote attackers to read arbitrary files on the server.
5
Is there a workaround for CVE-2016-10331 until I can apply a patch?
There are no official workarounds for CVE-2016-10331; updating to the latest version is strongly recommended.