CVE-2017-12079: Infoleak
Files or directories accessible to external parties vulnerability in picasa.php in Synology Photo Station before 6.8.1-3458 and before 6.3-2970 allows remote attackers to obtain arbitrary files via progid field.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-12079?
CVE-2017-12079 is a vulnerability that allows remote attackers to obtain arbitrary files in Synology Photo Station before 6.8.1-3458 and before 6.3-2970.
What is the severity of CVE-2017-12079?
The severity of CVE-2017-12079 is high with a CVSS score of 7.5.
How can the CVE-2017-12079 vulnerability be exploited?
The CVE-2017-12079 vulnerability can be exploited by remote attackers to obtain arbitrary files via the prog_id field in picasa.php.
Which software versions are affected by CVE-2017-12079?
The Synology Photo Station versions before 6.8.1-3458 and before 6.3-2970 are affected by CVE-2017-12079.
How can I fix the CVE-2017-12079 vulnerability?
To fix the CVE-2017-12079 vulnerability, it is recommended to update Synology Photo Station to version 6.8.1-3458 or 6.3-2970.