CVE-2017-15893: Path Traversal
Published Dec 8, 2017
·Updated
Directory traversal vulnerability in the SYNO.FileStation.Extract in Synology File Station before 1.1.1-0099 allows remote authenticated users to write arbitrary files via the destfolderpath parameter.
Affected Software
1 affected component
Synology File Station<1.1.1-0099
Event History
Dec 8, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-15893?
CVE-2017-15893 has a medium severity rating, indicating it can potentially lead to unauthorized file access.
2
How do I fix CVE-2017-15893?
To fix CVE-2017-15893, upgrade Synology File Station to version 1.1.1-0099 or later.
3
Who is affected by CVE-2017-15893?
Remote authenticated users of Synology File Station versions prior to 1.1.1-0099 are affected by CVE-2017-15893.
4
What kind of vulnerability is CVE-2017-15893?
CVE-2017-15893 is a directory traversal vulnerability that allows file writing via manipulated parameters.
5
Can CVE-2017-15893 be exploited remotely?
Yes, CVE-2017-15893 can be exploited remotely by authenticated users.