• Sign in

CVE-2015-9105

    CVE-2015-9105  
Description Multiple cross-site scripting (XSS) vulnerabilities in Synology Video Station 1.2 before 1.2-0455, 1.5 before 1.5-0772, and 1.6 before 1.6-0847 allow remote authenticated attackers to inject arbitrary web script or HTML via the (1) file name or (2) collection name of videos.
Impact
  CVSS v3 : 5.4 MEDIUM  

  CVSS v2 : 3.5 LOW  
Type
  CWE-79  
Attack Vector
CVSSv2 Vector : AV:N/AC:M/Au:S/C:N/I:P/A:N
Quick linksCVE, NVD, CERT, Metasploit, Exploit-db, Fulldisc, Bugtraq, Microsoft, Red Hat, Debian, GitHub code/issues, Google
References
http://www.fortiguard.com/zeroday/FG-VD-15-107
http://www.fortiguard.com/zeroday/FG-VD-15-108
https://www.synology.com/en-global/support/security/Video_station_1_5_0772
  • FAQ
  • Terms of service
  • Privacy policy