CVE-2017-11152: Path Traversal
Published Aug 8, 2017
·Updated
Directory traversal vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to write arbitrary files via the path parameter.
Affected Software
2 affected components
Synology Photo Station<=6.7.2-3429
Synology Photo Station=6.3-2967
Event History
Aug 8, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-11152?
CVE-2017-11152 is classified as a high severity vulnerability that allows remote attackers to write arbitrary files.
2
How do I fix CVE-2017-11152?
To fix CVE-2017-11152, upgrade Synology Photo Station to version 6.7.3-3432 or later, or version 6.3-2968 or later.
3
What versions of Synology Photo Station are affected by CVE-2017-11152?
CVE-2017-11152 affects Synology Photo Station versions prior to 6.7.3-3432 and version 6.3-2967.
4
What type of attack can exploit CVE-2017-11152?
CVE-2017-11152 can be exploited through a directory traversal attack that allows writing arbitrary files.
5
Is CVE-2017-11152 related to any specific file in Synology Photo Station?
CVE-2017-11152 specifically affects the PixlrEditorHandler.php file in Synology Photo Station.