First published: Fri Sep 08 2017(Updated: )
Multiple SQL injection vulnerabilities in Synology Photo Station before 6.7.4-3433 and 6.3-2968 allow remote attackers to execute arbitrary SQL commands via the (1) article_id parameter to label.php; or (2) type parameter to synotheme.php.
Credit: security@synology.com
Affected Software | Affected Version | How to fix |
---|---|---|
Synology Photo Station | <=6.3-2967 | |
Synology Photo Station | <=6.7.3-3432 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-11161 allows attackers to execute arbitrary SQL commands, which can lead to unauthorized data access and manipulation.
To mitigate CVE-2017-11161, users should upgrade Synology Photo Station to version 6.7.4-3433 or 6.3-2968 or later.
The affected versions of Synology Photo Station for CVE-2017-11161 include versions prior to 6.7.4-3433 and 6.3-2968.
Yes, CVE-2017-11161 is remotely exploitable, allowing attackers to execute SQL injection via specific parameters from a remote location.
The vulnerable parameters involved in CVE-2017-11161 are 'article_id' in label.php and 'type' in synotheme.php.