CVE-2017-11161: SQL Injection
Multiple SQL injection vulnerabilities in Synology Photo Station before 6.7.4-3433 and 6.3-2968 allow remote attackers to execute arbitrary SQL commands via the (1) articleid parameter to label.php; or (2) type parameter to synotheme.php.
Affected Software
Event History
Frequently Asked Questions
What are the potential impacts of CVE-2017-11161?
CVE-2017-11161 allows attackers to execute arbitrary SQL commands, which can lead to unauthorized data access and manipulation.
How can CVE-2017-11161 be mitigated in Synology Photo Station?
To mitigate CVE-2017-11161, users should upgrade Synology Photo Station to version 6.7.4-3433 or 6.3-2968 or later.
What versions of Synology Photo Station are affected by CVE-2017-11161?
The affected versions of Synology Photo Station for CVE-2017-11161 include versions prior to 6.7.4-3433 and 6.3-2968.
Is CVE-2017-11161 remotely exploitable?
Yes, CVE-2017-11161 is remotely exploitable, allowing attackers to execute SQL injection via specific parameters from a remote location.
What parameters are involved in the SQL injection for CVE-2017-11161?
The vulnerable parameters involved in CVE-2017-11161 are 'article_id' in label.php and 'type' in synotheme.php.