PT-2015-7399 · Synology · Video Station

Cengiz Han Sahin

·

Publicado

2015-09-11

·

Atualizado

2018-10-09

·

CVE-2015-6912

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Synology Video Station versions prior to 1.5-0763
Description The issue allows remote attackers to execute arbitrary shell commands. This is achieved by injecting shell metacharacters into the subtitle codepage parameter of the "subtitle.cgi" endpoint.
Recommendations For versions prior to 1.5-0763, update to version 1.5-0763 or later to resolve the issue. As a temporary workaround, consider restricting access to the subtitle.cgi endpoint to minimize the risk of exploitation. Avoid using the subtitle codepage parameter in the affected endpoint until the issue is resolved.

Exploit

Correção

Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-6912

Produtos afetados

Video Station